Description
MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1
Published: 2025-02-27
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5457 MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1
History

Wed, 09 Apr 2025 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft windows
Redhat
Redhat enterprise Linux For Arm 64
Redhat enterprise Linux For Ibm Z Systems
Redhat enterprise Linux Server For Power Little Endian Update Services For Sap Solutions
Redhat enterprise Linux Update Services For Sap Solutions
CPEs cpe:2.3:a:mongodb:compass:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_arm_64:9.0_aarch64:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:9.0_s390x:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:9.0_ppc64le:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.0:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows
Redhat
Redhat enterprise Linux For Arm 64
Redhat enterprise Linux For Ibm Z Systems
Redhat enterprise Linux Server For Power Little Endian Update Services For Sap Solutions
Redhat enterprise Linux Update Services For Sap Solutions

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 27 Feb 2025 16:45:00 +0000

Type Values Removed Values Added
References

Thu, 27 Feb 2025 15:30:00 +0000

Type Values Removed Values Added
Description MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1
Title MongoDB Compass may be susceptible to local privilege escalation in Windows
First Time appeared Mongodb
Mongodb compass
Weaknesses CWE-426
CPEs cpe:2.3:a:mongodb:compass:1.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.10:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.11:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.12:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.13:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.14:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.15:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.16:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.17:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.18:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.19:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.20:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.21:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.22:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.23:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.24.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.25.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.26.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.26.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.28.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.28.4:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.29.4:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.29.5:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.29.6:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.2:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.30.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.31.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.31.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.31.2:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.31.3:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.32.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.32.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.32.2:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.32.3:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.33.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.33.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.34.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.34.2:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.35.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.36.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.36.2:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.37.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.38.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.38.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.38.2:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.39.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.39.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.39.2:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.39.3:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.39.4:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.3:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.40.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.40.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.40.2:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.40.3:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.40.4:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.41.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.42.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.4:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.5:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.6:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.7:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.8:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.9:*:*:*:*:*:*:*
Vendors & Products Mongodb
Mongodb compass
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Microsoft Windows
Mongodb Compass
Redhat Enterprise Linux For Arm 64 Enterprise Linux For Ibm Z Systems Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions Enterprise Linux Update Services For Sap Solutions
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2025-02-27T16:07:45.320Z

Reserved: 2025-02-27T13:02:01.480Z

Link: CVE-2025-1755

cve-icon Vulnrichment

Updated: 2025-02-27T16:07:09.984Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-27T16:15:39.137

Modified: 2025-04-09T14:07:43.140

Link: CVE-2025-1755

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses