CVE-2025-23061 is a search injection vulnerability in Mongoose before 8.9.5 caused by improper handling of a nested MongoDB $where filter when used in a populate() match condition. The flaw allows attacker-controlled query structure to be interpreted as executable query logic rather than inert data, creating a NoSQL injection condition in applications that pass untrusted input into affected query construction paths. The issue is noted as resulting from an incomplete fix for CVE-2024-53900. Because $where enables JavaScript-based query evaluation in MongoDB, unsafe propagation of a nested $where inside populate() matching can let an attacker alter query semantics and potentially introduce arbitrary query predicates beyond the developer’s intended constraints.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a standalone Node.js proof-of-concept lab for CVE-2025-23061, an incomplete fix/bypass of the earlier Mongoose issue CVE-2024-53900. It contains a vulnerable Express application (server.js), an exploit driver (exploit.js), Docker Compose for MongoDB, package metadata, and a placeholder scanner.js. The core issue is unsafe use of attacker-controlled input in Mongoose populate() options, especially nested $where operators inside logical operators such as $and/$or, which are not properly sanitized in affected Mongoose versions. Repository structure: server.js implements the vulnerable demo service and seeds test data; exploit.js sends crafted HTTP requests to trigger the bug; docker-compose.yml provisions MongoDB 7.0 on port 27017; package.json/package-lock.json define dependencies including express, debug, and mongoose 8.9.4; README.md documents affected versions, setup, and example payloads; scanner.js is non-functional placeholder content. Main exploit capabilities: The exploit can initialize the lab via POST /setup, then send malicious populate match/query objects to GET /posts, GET /posts-2, or POST /posts/search. Demonstrated outcomes include unauthorized retrieval of admin-associated data using predicates like this.isAdmin, broad data extraction using always-true conditions, field/property enumeration, denial of service via sleep() or infinite loops, and attempted process-level impact/RCE-style behavior through expressions referencing global.process, child_process, fs, and outbound HTTPS requests. The active exploit path in exploit.js targets /posts-2 with a crafted populate object and a $where expression that attempts process termination via global.process.exit(1). Overall, this is a real exploit PoC rather than a detector. It is operational because it includes both a vulnerable target application and working exploit requests, though payloads are mostly hardcoded demonstrations rather than a generalized exploitation framework.
This repository is a small, self-contained lab environment for CVE-2025-23061 built as a vulnerable Express/Mongoose application backed by MongoDB. It is not part of a larger exploit framework. The repo contains four files: server.js with the vulnerable application logic, package.json defining Node dependencies, a Dockerfile that installs Node 18 and MongoDB 7.0 in one container, and docker-compose.yml that provisions separate mongodb and web-app services. The main exploit capability is server-side injection into MongoDB/Mongoose query construction via unsafely parsed JSON query parameters. In server.js, the /posts endpoint accepts req.query.authorMatch and req.query.sort, parses them with JSON.parse(), and passes them directly into Post.find().populate({ match, options.sort }). This allows attacker influence over populate filtering and sorting behavior. The /api/users/:userId/posts endpoint similarly parses a filters parameter and merges attacker-controlled criteria into populateConfig.match, creating a second injection surface. The /api/stats endpoint parses userFilter and inserts it directly into an aggregation pipeline $match stage, enabling attacker-controlled aggregation filtering. The application seeds test data on startup: an admin user, a normal user, a public post, and an admin post. This indicates the lab is intended to demonstrate unauthorized data exposure or logic manipulation rather than remote code execution. The likely outcome of exploitation is retrieval or selective exposure of records associated with privileged users, plus manipulation of aggregate statistics. Notable network/application endpoints are GET /posts, GET /api/users/:userId/posts, and GET /api/stats. The app listens on port 80. MongoDB is exposed on 27017 in docker-compose. There is a configuration inconsistency: server.js hardcodes mongodb://localhost:27017/testdb, while docker-compose sets MONGODB_URI=mongodb://mongodb:27017/cve_lab; the code does not consume that environment variable. Also, the Dockerfile exposes port 3000 while the app actually listens on 80. Despite these inconsistencies, the repository clearly functions as an operational vulnerable lab/PoC for query injection against Mongoose 8.9.4 and MongoDB-backed endpoints.
This repository is a Proof of Concept (PoC) for CVE-2025-23061, a critical NoSQL injection vulnerability in Mongoose (< 8.9.5) affecting the populate() function's match option. The repository contains 8 files, with the main code in 'server.js' (vulnerable server) and 'exploit.js' (exploit script). The server exposes several endpoints, notably '/posts', '/posts-2', and '/posts/search', all of which are vulnerable to NoSQL injection via unsanitized user input in the match parameter. The exploit demonstrates how an attacker can inject JavaScript expressions (including $where operators nested in logical operators) to bypass authentication, enumerate users, extract sensitive data, and potentially achieve remote code execution (RCE) or denial of service (DoS) on the MongoDB server. The exploit payloads include both data extraction and RCE attempts (e.g., reading /etc/passwd or writing to /tmp). The repository is structured for easy setup and testing, with a Docker Compose file for MongoDB and scripts for initializing test data. This PoC is intended for educational and testing purposes only.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prior Mongoose search injection vulnerability related to the $where clause, mentioned as historical context for recurring query sanitization issues.
A critical vulnerability in Mongoose (prior to 8.9.5) allowing attackers to manipulate MongoDB queries via improper handling of nested $where filters and the populate() function, leading to search injection.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.