← Back to CVE List

CVE-2019-10758

Published: 2019-12-24T22:15Z
Last Modified: 2025-03-13T17:27Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt