CVE-2025-1755

MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1
References
Link Resource
https://jira.mongodb.org/browse/COMPASS-9058 Vendor Advisory Issue Tracking
https://access.redhat.com/errata/RHSA-2025:1755.html Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:mongodb:compass:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:redhat:enterprise_linux_for_arm_64:9.0_aarch64:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:9.0_s390x:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:9.0_ppc64le:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.0:*:*:*:*:*:*:*

History

09 Apr 2025, 14:07

Type Values Removed Values Added
References () https://jira.mongodb.org/browse/COMPASS-9058 - () https://jira.mongodb.org/browse/COMPASS-9058 - Vendor Advisory, Issue Tracking
References () https://access.redhat.com/errata/RHSA-2025:1755.html - () https://access.redhat.com/errata/RHSA-2025:1755.html - Third Party Advisory
CPE cpe:2.3:a:mongodb:compass:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.0:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:9.0_s390x:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_arm_64:9.0_aarch64:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:9.0_ppc64le:*:*:*:*:*:*:*
Summary
  • (es) MongoDB Compass puede ser susceptible a una escalada de privilegios locales en determinadas condiciones, lo que podría permitir acciones no autorizadas en el sistema de un usuario con privilegios elevados, cuando un archivo manipulado se almacena en C:\node_modules\. Este problema afecta a MongoDB Compass anterior a la versión 1.42.1.
First Time Mongodb compass
Redhat
Mongodb
Microsoft
Redhat enterprise Linux For Arm 64
Microsoft windows
Redhat enterprise Linux Update Services For Sap Solutions
Redhat enterprise Linux Server For Power Little Endian Update Services For Sap Solutions
Redhat enterprise Linux For Ibm Z Systems

27 Feb 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-27 16:15

Updated : 2025-04-09 14:07


NVD link : CVE-2025-1755

Mitre link : CVE-2025-1755

CVE.ORG link : CVE-2025-1755


JSON object : View

Products Affected

microsoft

  • windows

redhat

  • enterprise_linux_for_arm_64
  • enterprise_linux_for_ibm_z_systems
  • enterprise_linux_update_services_for_sap_solutions
  • enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions

mongodb

  • compass
CWE
CWE-426

Untrusted Search Path