npm package intelligence

mongo-express Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the npm package mongo-express, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
1
Known exploited vulnerability affecting mongo-express
In CISA KEV
1
Records also listed in the official catalog
Beyond CISA KEV
0
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
mongo-express KEVs with sensor-observed exploitation activity

Review mongo-express exploitation against the versions you run

All one exploited mongo-express vulnerability tracked here is also listed in CISA KEV.

100%
Covered by CISA
0%
Beyond CISA

Attested mongo-express vulnerabilities

1 known exploited vulnerability affecting this package.

Vulnerability CISA KEV Added
CVE-2019-10758

mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to...

In CISA 10 Dec 2021

Recurring weakness patterns

Improper Control of Generation of Code ('Code Injection') account for mapped occurrences across this mongo-express KEV portfolio.

Browse all KEVs →