by @mweinelt Activity log
- Created automatic suggestion
-
@mweinelt
removed
33 packages
- mongodb
- mongodb-ce
- mongodb-6_0
- mongodb-7_0
- mongodb-cli
- mongodb-compass
- mongodb-atlas-cli
- perlPackages.MongoDB
- phpExtensions.mongodb
- haskellPackages.mongoDB
- perl538Packages.MongoDB
- perl540Packages.MongoDB
- php81Extensions.mongodb
- php82Extensions.mongodb
- php83Extensions.mongodb
- php84Extensions.mongodb
- php85Extensions.mongodb
- akkuPackages.r6rs-mongodb
- prometheus-mongodb-exporter
- haskellPackages.pipes-mongodb
- graylogPlugins.mongodb-profiler
- terraform-providers.mongodbatlas
- python312Packages.langchain-mongodb
- python313Packages.langchain-mongodb
- python314Packages.langchain-mongodb
- terraform-providers.mongodb_mongodbatlas
- vscode-extensions.mongodb.mongodb-vscode
- python312Packages.langgraph-store-mongodb
- python313Packages.langgraph-store-mongodb
- python314Packages.langgraph-store-mongodb
- python312Packages.langgraph-checkpoint-mongodb
- python313Packages.langgraph-checkpoint-mongodb
- python314Packages.langgraph-checkpoint-mongodb
- @mweinelt dismissed
NoSQL Injection via WebSocket id Parameter in MongoDB Adapter
Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. From 5.0.0 to before 5.0.42, Socket.IO clients can send arbitrary JavaScript objects as the id argument to any service method (get, patch, update, remove). The transport layer performs no type checking on this argument. When the service uses the MongoDB adapter, these objects pass through getObjectId() and land directly in the MongoDB query as operators. Sending {$ne: null} as the id matches every document in the collection. This vulnerability is fixed in 5.0.42.
References
- https://github.com/feathersjs/feathers/security/advisories/GHSA-p9xr-7p9p-gpqx x_refsource_CONFIRM
Affected products
- ==>= 5.0.0, < 5.0.42
Ignored packages (33)
pkgs.mongodb
Scalable, high-performance, open source NoSQL database
pkgs.mongodb-ce
MongoDB is a general purpose, document-based, distributed database.
pkgs.mongodb-6_0
Scalable, high-performance, open source NoSQL database
pkgs.mongodb-7_0
Scalable, high-performance, open source NoSQL database
pkgs.mongodb-cli
MongoDB CLI enable you to manage your MongoDB via ops manager and cloud manager
pkgs.mongodb-compass
GUI for MongoDB
pkgs.mongodb-atlas-cli
CLI utility to manage MongoDB Atlas from the terminal
pkgs.perlPackages.MongoDB
Official MongoDB Driver for Perl (EOL)
pkgs.phpExtensions.mongodb
Official MongoDB PHP driver
pkgs.haskellPackages.mongoDB
Driver (client) for MongoDB, a free, scalable, fast, document DBMS
pkgs.perl538Packages.MongoDB
Official MongoDB Driver for Perl (EOL)
pkgs.perl540Packages.MongoDB
Official MongoDB Driver for Perl (EOL)
pkgs.php81Extensions.mongodb
Official MongoDB PHP driver
pkgs.php82Extensions.mongodb
Official MongoDB PHP driver
pkgs.php83Extensions.mongodb
Official MongoDB PHP driver
pkgs.php84Extensions.mongodb
Official MongoDB PHP driver
pkgs.php85Extensions.mongodb
Official MongoDB PHP driver
pkgs.akkuPackages.r6rs-mongodb
MongoDB client and BSON
-
nixos-unstable r6rs-mongodb-0.0.190423
- nixpkgs-unstable r6rs-mongodb-0.0.190423
- nixos-unstable-small r6rs-mongodb-0.0.190423
-
nixos-25.11 r6rs-mongodb-0.0.190423
- nixos-25.11-small r6rs-mongodb-0.0.190423
- nixpkgs-25.11-darwin r6rs-mongodb-0.0.190423
pkgs.prometheus-mongodb-exporter
Prometheus exporter for MongoDB including sharding, replication and storage engines
pkgs.haskellPackages.pipes-mongodb
Stream results from MongoDB
pkgs.graylogPlugins.mongodb-profiler
Graylog input plugin that reads MongoDB profiler data
pkgs.terraform-providers.mongodbatlas
None
pkgs.python312Packages.langchain-mongodb
Integration package connecting MongoDB and LangChain
pkgs.python313Packages.langchain-mongodb
Integration package connecting MongoDB and LangChain
pkgs.python314Packages.langchain-mongodb
Integration package connecting MongoDB and LangChain
pkgs.terraform-providers.mongodb_mongodbatlas
None
pkgs.vscode-extensions.mongodb.mongodb-vscode
An extension for VS Code that makes it easy to work with your data in MongoDB
pkgs.python312Packages.langgraph-store-mongodb
Integrations between MongoDB, Atlas, LangChain, and LangGraph
pkgs.python313Packages.langgraph-store-mongodb
Integrations between MongoDB, Atlas, LangChain, and LangGraph
pkgs.python314Packages.langgraph-store-mongodb
Integrations between MongoDB, Atlas, LangChain, and LangGraph
pkgs.python312Packages.langgraph-checkpoint-mongodb
Integrations between MongoDB, Atlas, LangChain, and LangGraph
pkgs.python313Packages.langgraph-checkpoint-mongodb
Integrations between MongoDB, Atlas, LangChain, and LangGraph
pkgs.python314Packages.langgraph-checkpoint-mongodb
Integrations between MongoDB, Atlas, LangChain, and LangGraph