Vulnerability Description
The MongoDB Shell may be susceptible to control character injection where an attacker with control of the user’s clipboard could manipulate them to paste text into mongosh that evaluates arbitrary code. Control characters in the pasted text can be used to obfuscate malicious code. This issue affects mongosh versions prior to 2.3.9
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mongodb | Mongosh | < 2.3.9 |
Related Weaknesses (CWE)
References
- https://jira.mongodb.org/browse/MONGOSH-2025Issue TrackingVendor Advisory
FAQ
What is CVE-2025-1692?
CVE-2025-1692 is a vulnerability with a CVSS score of 6.3 (MEDIUM). The MongoDB Shell may be susceptible to control character injection where an attacker with control of the user’s clipboard could manipulate them to paste text into mongosh that evaluates arbitrary cod...
How severe is CVE-2025-1692?
CVE-2025-1692 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-1692?
Check the references section above for vendor advisories and patch information. Affected products include: Mongodb Mongosh.