{"id":"CVE-2025-6713","summary":"MongoDB Server may be susceptible to privilege escalation due to $mergeCursors stage","details":"An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server. This may lead to access to data without further authorisation. This issue affects MongoDB Server MongoDB Server v8.0 versions prior to 8.0.7, MongoDB Server v7.0 versions prior to 7.0.19 and MongoDB Server v6.0 versions prior to 6.0.22","aliases":["BIT-mongodb-2025-6713"],"modified":"2026-08-12T15:14:43.539432Z","published":"2025-07-07T14:46:36.201Z","database_specific":{"cwe_ids":["CWE-285"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/6xxx/CVE-2025-6713.json","unresolved_ranges":[{"extracted_events":[{"introduced":"6.0"},{"fixed":"6.0.22"},{"introduced":"7.0"},{"fixed":"7.0.19"},{"introduced":"8.0"},{"fixed":"8.0.7"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"mongodb"},"references":[{"type":"WEB","url":"https://jira.mongodb.org/browse/SERVER-106752"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/6xxx/CVE-2025-6713.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-6713"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mongodb/mongo","events":[{"introduced":"e61bf27c2f6a83fed36e5a13c008a32d563babe2"},{"fixed":"fc15786481d4e5e9ae1192425944e19d446a418e"},{"introduced":"37d84072b5c5b9fd723db5fa133fb202ad2317f1"},{"fixed":"6cf88233f0c649695862b1b5be20c04b87f7e8f1"},{"introduced":"b41cda4fe697dce6fd9b83b3805362ccc02fbeb3"},{"fixed":"f2b89463945f47376156f270dbf193f74484a623"}],"database_specific":{"cpe":"cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*","extracted_events":[{"introduced":"6.0.0"},{"fixed":"6.0.22"},{"introduced":"7.0.0"},{"fixed":"7.0.19"},{"introduced":"8.0.0"},{"fixed":"8.0.7"}],"source":"CPE_RANGE"}}],"versions":["r7.0.18","r6.0.21","r8.0.6","r7.0.17","r8.0.5-rc2","r8.0.5","r8.0.5-rc1","r8.0.5-rc0","r6.0.20-rc3","r6.0.20","r6.0.20-rc2","r6.0.20-rc1","r6.0.20-rc0","r7.0.16-rc1","r7.0.16-rc0","r7.0.16","r8.0.4-rc0","r8.0.4","r6.0.19","r7.0.15","r8.0.3","r8.0.2","r7.0.15-rc1","r7.0.15-rc0","r8.0.1-rc0","r8.0.1","r8.0.0","r6.0.18-rc0","r6.0.18","r7.0.14-rc0","r7.0.14","r7.0.13-rc1","r7.0.13","r6.0.17-rc0","r6.0.17","r7.0.13-rc0","r7.0.12-rc1","r7.0.12","r7.0.12-rc0","r6.0.16-rc0","r6.0.16","r7.0.11-rc2","r7.0.11","r7.0.11-rc1","r7.0.11-rc0","r7.0.10-rc0","r7.0.10","r7.0.9-rc1","r7.0.9","r7.0.9-rc0","r6.0.15-rc0","r6.0.15","r7.0.8-rc0","r7.0.8","r7.0.7-rc2","r7.0.7","r7.0.7-rc1","r7.0.7-rc0","r6.0.14-rc1","r6.0.14","r7.0.6-rc0","r7.0.6","r6.0.14-rc0","r6.0.13-rc0","r6.0.13","r7.0.5-rc0","r7.0.5","r6.0.12-rc1","r6.0.12","r7.0.4-rc0","r7.0.4","r6.0.12-rc0","r7.0.3-rc1","r7.0.3","r7.0.3-rc0","r6.0.11-rc0","r6.0.11","r7.0.2-rc2","r7.0.2","r7.0.2-rc1","r7.0.2-rc0","r6.0.10-rc0","r6.0.10","r7.0.1-rc0","r7.0.1","r7.0.0","r6.0.9-rc1","r6.0.9","r6.0.9-rc0","r6.0.8-rc0","r6.0.8","r6.0.7-rc0","r6.0.7","r6.0.6-rc1","r6.0.6","r6.0.6-rc0","r6.0.5-rc1","r6.0.5","r6.0.5-rc0","r6.0.4-rc1","r6.0.4-rc0","r6.0.4","r6.0.3-rc2","r6.0.3-rc1","r6.0.3","r6.0.3-rc0","r6.0.2-rc1","r6.0.2","r6.0.2-rc0","r6.0.1-rc0","r6.0.1","r6.0.0"],"database_specific":{"vanir_signatures":[{"signature_version":"v1","source":"https://github.com/mongodb/mongo/commit/6cf88233f0c649695862b1b5be20c04b87f7e8f1","target":{"file":"src/mongo/db/pipeline/lite_parsed_document_source.h"},"deprecated":false,"digest":{"line_hashes":["214643683530774032100036489942452737529","318477943940252881987496373792852256683","198474435809438694509794776280487724710"],"threshold":0.9},"id":"CVE-2025-6713-0b4e0751","signature_type":"Line"},{"id":"CVE-2025-6713-2653d96c","signature_type":"Line","signature_version":"v1","source":"https://github.com/mongodb/mongo/commit/6cf88233f0c649695862b1b5be20c04b87f7e8f1","target":{"file":"src/mongo/s/query/document_source_merge_cursors.cpp"},"deprecated":false,"digest":{"line_hashes":["138467260949863329498805639538379507808","223198180086728900778837498337912589521","148430034972700418827909772528237080451","98898776309116250111447806208156160681","140132014256917882686791854219027715215","2073529888411466178012965154365761325","23439098951180303377135904545527049056"],"threshold":0.9}},{"id":"CVE-2025-6713-5690edc3","signature_type":"Line","signature_version":"v1","source":"https://github.com/mongodb/mongo/commit/f2b89463945f47376156f270dbf193f74484a623","target":{"file":"src/mongo/s/query/document_source_merge_cursors.cpp"},"deprecated":false,"digest":{"line_hashes":["167971444258294881142130961071240963937","40580703834568146500067455680138133324","148430034972700418827909772528237080451","98898776309116250111447806208156160681","140132014256917882686791854219027715215","2073529888411466178012965154365761325","23439098951180303377135904545527049056"],"threshold":0.9}},{"target":{"file":"src/mongo/s/query/document_source_merge_cursors.cpp"},"deprecated":false,"digest":{"line_hashes":["138467260949863329498805639538379507808","223198180086728900778837498337912589521","148430034972700418827909772528237080451","98898776309116250111447806208156160681","140132014256917882686791854219027715215","2073529888411466178012965154365761325","23439098951180303377135904545527049056"],"threshold":0.9},"id":"CVE-2025-6713-59c2835d","signature_type":"Line","signature_version":"v1","source":"https://github.com/mongodb/mongo/commit/fc15786481d4e5e9ae1192425944e19d446a418e"},{"target":{"file":"src/mongo/db/pipeline/lite_parsed_document_source.h"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["214643683530774032100036489942452737529","318477943940252881987496373792852256683","198474435809438694509794776280487724710"]},"id":"CVE-2025-6713-ddf202f8","signature_type":"Line","signature_version":"v1","source":"https://github.com/mongodb/mongo/commit/f2b89463945f47376156f270dbf193f74484a623"},{"target":{"file":"src/mongo/db/pipeline/lite_parsed_document_source.h"},"deprecated":false,"digest":{"line_hashes":["214643683530774032100036489942452737529","318477943940252881987496373792852256683","198474435809438694509794776280487724710"],"threshold":0.9},"id":"CVE-2025-6713-fb98bdd7","signature_type":"Line","signature_version":"v1","source":"https://github.com/mongodb/mongo/commit/fc15786481d4e5e9ae1192425944e19d446a418e"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-6713.json","vanir_signatures_modified":"2026-08-12T15:14:43Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"}]}