<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T19:05:21.558766+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-mongoose-2026-73562</id>
    <title>BIT-mongoose-2026-73562 — Mongoose: Prototype pollution in the update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)</title>
    <updated>2026-10-08T19:05:21.609311+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: mongoose</p>
<p>Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.24.1, and 9.7.2, passing a user-controlled update such as MyModel.updateOne(filter, req.body) can exploit Mongoose update casting with a __proto__.x dotted path under $set. Schema.prototype.path and Schema.prototype._getPathType can treat inherited properties of schema.paths and schema.nested as schema types, allowing the casting process to set $fullPath and $parentSchemaDocArray on Object.prototype before throwing. This prototype pollution makes those properties visible on newly created objects and can cause application integrity and availability impacts. This issue is fixed in versions 6.13.10, 7.8.10, 8.24.1, and 9.7.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-mongoose-2026-73562"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352839</id>
    <title>EUVD-2026-352839</title>
    <updated>2026-10-08T19:05:21.609375+00:00</updated>
    <content>EUVD-2026-352839</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352839"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73562</id>
    <title>fkie_cve-2026-73562</title>
    <updated>2026-10-08T19:05:21.609392+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.24.1, and 9.7.2, passing a user-controlled update such as MyModel.updateOne(filter, req.body) can exploit Mongoose update casting with a __proto__.x dotted path under $set. Schema.prototype.path and Schema.prototype._getPathType can treat inherited properties of schema.paths and schema.nested as schema types, allowing the casting process to set $fullPath and $parentSchemaDocArray on Object.prototype before throwing. This prototype pollution makes those properties visible on newly created objects and can cause application integrity and availability impacts. This issue is fixed in versions 6.13.10, 7.8.10, 8.24.1, and 9.7.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-73562"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-664h-wqgq-64gw</id>
    <title>GHSA-664h-wqgq-64gw — Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path get…</title>
    <updated>2026-10-08T19:05:21.609418+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: mongoose</p>
<p>### Impact
_What kind of vulnerability is it? Who is impacted?_</p>
<p>Prototype pollution in update casting: passing a user-controlled update to a Mongoose update, like `MyModel.updateOne(filter, req.body)`, can cause Mongoose to set `$fullPath` and `$parentSchemaDocArray` on `Object.prototype`.</p>
<p>Example:</p>
<p>```javascript
const mongoose = require('mongoose');
console.log('before:', Object.prototype.$fullPath);            // undefined</p>
<p>const User = mongoose.model('User', new mongoose.Schema({ name: String }));
const malicious = JSON.parse('{"$set": {"__proto__.x": "anything"}}');   // attacker-controlled update</p>
<p>const q = User.updateOne({}, {});
try { q._castUpdate(malicious); } catch (e) { /* throws AFTER the pollution side-effect */ }</p>
<p>console.log('after :', Object.prototype.$fullPath);            // "__proto__"
console.log('enumerable:', Object.prototype.propertyIsEnumerable('$fullPath'));  // true
console.log('fresh {}:', ({}).$fullPath);                      // "__proto__"
```</p>
<p>### Patches
_Has the problem been patched? What versions should users upgrade to?_</p>
<p>9.7.2, 8.24.1. 7.8.10, 6.13.10</p>
<p>### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_</p>
<p>Check user-controlled updates for own `__proto__` properties before passing to Mongoose</p>
<p>### References
_Are there any links users can visit to find out more?_</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-664h-wqgq-64gw"/>
  </entry>
</feed>
