{"id":"CVE-2026-84967","summary":"Arbitrary command execution via shell-expanded connection string in Launch MongoDB Shell terminal","details":"A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into a command line the extension composes for an integrated terminal. An unauthenticated remote unauthorized-user who persuades a developer to accept a user-supplied connection target, and then to open the extension's shell feature, can place characters of the unauthorized-user’s choosing into that command line. No privileges on the developer's machine are required, but several user actions are. The confirmation the developer sees does not display the supplied text.","aliases":["BIT-mongodb-2026-84967"],"modified":"2026-09-11T03:48:44.422326544Z","published":"2026-09-03T15:18:02.017Z","database_specific":{"cwe_ids":["CWE-78"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84967.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"1.13.0"},{"fixed":"1.17.1"}]}],"cna_assigner":"mongodb"},"references":[{"type":"WEB","url":"https://jira.mongodb.org/browse/VSCODE-798"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84967.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84967"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mongodb-js/vscode","events":[{"introduced":"77c419e4ec08e8324a0733b95cb746e242129e5d"},{"fixed":"107e63212800bc95e64ef7fa6f5384d9f315d85f"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:visual_studio_code:*:*","extracted_events":[{"introduced":"1.13.0"},{"fixed":"1.17.1"}]}}],"versions":["v1.17.0","v1.16.1","v1.16.0","v1.15.1","v1.15.0","v1.14.6","v1.14.5","v1.14.4","v1.14.3","v1.14.2","v1.14.1","v1.14.0","v1.13.3","v1.13.2","v1.13.1","v1.13.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84967.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}