CVE-2025-1755

MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1
References
Link Resource
https://jira.mongodb.org/browse/COMPASS-9058 Vendor Advisory Issue Tracking
https://access.redhat.com/errata/RHSA-2025:1755.html Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:mongodb:compass:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:redhat:enterprise_linux_for_arm_64:9.0_aarch64:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:9.0_s390x:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:9.0_ppc64le:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.0:*:*:*:*:*:*:*

History

09 Apr 2025, 14:07

Type Values Removed Values Added
References () https://jira.mongodb.org/browse/COMPASS-9058 - () https://jira.mongodb.org/browse/COMPASS-9058 - Vendor Advisory, Issue Tracking
References () https://access.redhat.com/errata/RHSA-2025:1755.html - () https://access.redhat.com/errata/RHSA-2025:1755.html - Third Party Advisory
First Time Mongodb
Mongodb compass
Redhat enterprise Linux For Arm 64
Redhat enterprise Linux For Ibm Z Systems
Redhat
Microsoft
Redhat enterprise Linux Server For Power Little Endian Update Services For Sap Solutions
Redhat enterprise Linux Update Services For Sap Solutions
Microsoft windows
Summary
  • (es) MongoDB Compass puede ser susceptible a una escalada de privilegios locales en determinadas condiciones, lo que podría permitir acciones no autorizadas en el sistema de un usuario con privilegios elevados, cuando un archivo manipulado se almacena en C:\node_modules\. Este problema afecta a MongoDB Compass anterior a la versión 1.42.1.
CPE cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:9.0_s390x:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.0:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_arm_64:9.0_aarch64:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:9.0_ppc64le:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:*:*:*:*:*:*:*:*

27 Feb 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-27 16:15

Updated : 2025-04-09 14:07


NVD link : CVE-2025-1755

Mitre link : CVE-2025-1755

CVE.ORG link : CVE-2025-1755


JSON object : View

Products Affected

redhat

  • enterprise_linux_update_services_for_sap_solutions
  • enterprise_linux_for_arm_64
  • enterprise_linux_for_ibm_z_systems
  • enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions

mongodb

  • compass

microsoft

  • windows
CWE
CWE-426

Untrusted Search Path