← Back to search

CVE-2026-93759

8.6 HIGH

Published 2026-09-18 · Updated 2026-09-24

AI risk analysis

Summary
The flaw allows an unauthenticated attacker to inject server-side JavaScript code into MongoDB queries via the Mongoid ORM, potentially leading to data exposure and performance degradation.
Exploitability
Exploitation requires control over the query parameter supplied to Mongoid, making it moderately hard to exploit without access to the application's input flow.
Blast radius
If exploited, the impact could range from data leakage to performance issues, affecting any application using Mongoid for database interactions.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the affected Mongoid feature or upgrade to a version that mitigates this vulnerability, such as Mongoid 7.0.0 or later.
rceweborm

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as a query argument may cause code of their choosing to be evaluated by the database engine. This may result in unintended disclosure of stored field values, unintended selection of documents for application-initiated writes, and reduced database performance.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

Weaknesses

CWE-94

Vendors

mongodb

Products

mongoid

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.