{"id":"CVE-2026-93765","published":"2026-09-18T17:17:07.730","lastModified":"2026-09-21T19:17:18.297","description":"Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal method invocation instead of the intended array field update. This may result in unintended removal of stored records and in the embedding application becoming unresponsive.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","cwes":["CWE-470"],"vendors":[],"products":[],"references":[{"url":"https://jira.mongodb.org/browse/MONGOID-5973","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This flaw in Mongoid allows unauthenticated input to trigger unintended internal method invocations, potentially leading to data loss and application unresponsiveness.","exploitability":"Exploitation requires unauthenticated input with specific keys, making it moderately difficult. The embedding application must be configured to use Mongoid.","blast_radius":"If exploited, this could result in significant data loss and application downtime, impacting the entire system.","remediation":"Upgrade to the latest version of Mongoid, specifically version 6.3.0 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["data-loss","unauthenticated","internal-method-invocation"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T09:06:49.307Z"}}