Laravel 与 MongoDB 集成中,由于在数据查询逻辑中未能正确中和(neutralize)特殊元素,导致通过显式等值过滤条件传入的数组可能被解释为查询条件,而非字面值。此问题影响使用 或 运算符的三参数 方法,以及使用相同代码路径的 和 方法。如果攻击者能够促使受影响的应用程序向这些 API 之一提供“形似运算符”的数组,则可能获取到非预期目标的文档,或超出预期目标删除文档。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MongoDB | Laravel MongoDB (PHP) | 1.0.0< 5.11.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MongoDB | Laravel MongoDB (PHP) | 1.0.0 ~ 5.11.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88024 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88023 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88025 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88030 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88029 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88034 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88033 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88036 | 8.3 HIGH | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoD |
| CVE-2026-88031 | 8.1 HIGH | GridFS data deletion via query-operator injection in file IDs in the MongoDB Go Driver |
| CVE-2026-88027 | 7.1 HIGH | Mass deletion and overwrite of embedded documents via query-operator injection in embedded |
| CVE-2026-88026 | 6.5 MEDIUM | Regular expression injection via unescaped characters in LINQ query translation in MongoDB |
| CVE-2026-88028 | 6.5 MEDIUM | Unauthorized document disclosure via query-operator injection in polymorphic relation iden |
| CVE-2026-88032 | 5.9 MEDIUM | Application denial of service via cancellation race in reactive client-side encryption in |
| CVE-2026-88035 | 4.7 MEDIUM | Heap buffer overflow via wrapped size check during SASL username canonicalization in Mongo |
No comments yet