Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-73562— Mongoose: Prototype pollution in the update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)

Quick assessment

Affected
Automattic mongoose
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Mongoose 是一个用于异步环境的 MongoDB 对象建模工具。在版本 6.13.10、7.8.10、8.24.1 和 9.7.2 之前,若通过传递用户可控的更新操作(例如 ),攻击者可以利用 Mongoose 的更新类型转换机制,在 操作中使用形如 的点分路径进行注入。这种不当处理可能导致 和 将继承自 和 的内置属性误识别为 schema 类型,从而在抛出异常前,将 和 等属性设置到 上。该原型污染漏洞会使这些属性在后续创建的新对象中可见,进而可能导致应用程序完整性与可用性问题。该问题已在版本 6.13.

CVSS 6.5 · Medium EPSS 0.50% · P41

Possible ATT&CK Techniques 1 AI

T1552 · Unsecured Credentials

Affected Version Matrix 4

VendorProduct Version RangeStatus
Automattic mongoose < 6.13.10 affected
>= 7.0.0, < 7.8.10 affected
>= 8.0.0, < 8.24.1 affected
>= 9.0.0, < 9.7.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-73562

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Mongoose: Prototype pollution in the update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)
Source: CVE Program / CVE List V5
Vulnerability Description
Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.24.1, and 9.7.2, passing a user-controlled update such as MyModel.updateOne(filter, req.body) can exploit Mongoose update casting with a __proto__.x dotted path under $set. Schema.prototype.path and Schema.prototype._getPathType can treat inherited properties of schema.paths and schema.nested as schema types, allowing the casting process to set $fullPath and $parentSchemaDocArray on Object.prototype before throwing. This prototype pollution makes those properties visible on newly created objects and can cause application integrity and availability impacts. This issue is fixed in versions 6.13.10, 7.8.10, 8.24.1, and 9.7.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1321
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Automattic mongoose < 6.13.10 -

II. Public POCs for CVE-2026-73562

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-73562

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-73562 (4)

Vendor Advisories for CVE-2026-73562 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-73562

No comments yet


Leave a comment