<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 02:15:43 +0000</lastBuildDate>
    <item>
      <title>BIT-mongoose-2026-73562 — Mongoose: Prototype pollution in the update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)</title>
      <link>https://cve.radiocsirt.org/vuln/bit-mongoose-2026-73562</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: mongoose&lt;/p&gt;
&lt;p&gt;Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.24.1, and 9.7.2, passing a user-controlled update such as MyModel.updateOne(filter, req.body) can exploit Mongoose update casting with a __proto__.x dotted path under $set. Schema.prototype.path and Schema.prototype._getPathType can treat inherited properties of schema.paths and schema.nested as schema types, allowing the casting process to set $fullPath and $parentSchemaDocArray on Object.prototype before throwing. This prototype pollution makes those properties visible on newly created objects and can cause application integrity and availability impacts. This issue is fixed in versions 6.13.10, 7.8.10, 8.24.1, and 9.7.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: mongoose&lt;/p&gt;
&lt;p&gt;Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.24.1, and 9.7.2, passing a user-controlled update such as MyModel.updateOne(filter, req.body) can exploit Mongoose update casting with a __proto__.x dotted path under $set. Schema.prototype.path and Schema.prototype._getPathType can treat inherited properties of schema.paths and schema.nested as schema types, allowing the casting process to set $fullPath and $parentSchemaDocArray on Object.prototype before throwing. This prototype pollution makes those properties visible on newly created objects and can cause application integrity and availability impacts. This issue is fixed in versions 6.13.10, 7.8.10, 8.24.1, and 9.7.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-mongoose-2026-73562</guid>
    </item>
    <item>
      <title>EUVD-2026-352839</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352839</link>
      <description>EUVD-2026-352839</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352839</guid>
    </item>
    <item>
      <title>fkie_cve-2026-73562</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73562</link>
      <description>&lt;p&gt;Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.24.1, and 9.7.2, passing a user-controlled update such as MyModel.updateOne(filter, req.body) can exploit Mongoose update casting with a __proto__.x dotted path under $set. Schema.prototype.path and Schema.prototype._getPathType can treat inherited properties of schema.paths and schema.nested as schema types, allowing the casting process to set $fullPath and $parentSchemaDocArray on Object.prototype before throwing. This prototype pollution makes those properties visible on newly created objects and can cause application integrity and availability impacts. This issue is fixed in versions 6.13.10, 7.8.10, 8.24.1, and 9.7.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.24.1, and 9.7.2, passing a user-controlled update such as MyModel.updateOne(filter, req.body) can exploit Mongoose update casting with a __proto__.x dotted path under $set. Schema.prototype.path and Schema.prototype._getPathType can treat inherited properties of schema.paths and schema.nested as schema types, allowing the casting process to set $fullPath and $parentSchemaDocArray on Object.prototype before throwing. This prototype pollution makes those properties visible on newly created objects and can cause application integrity and availability impacts. This issue is fixed in versions 6.13.10, 7.8.10, 8.24.1, and 9.7.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-73562</guid>
    </item>
    <item>
      <title>GHSA-664h-wqgq-64gw — Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path get…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-664h-wqgq-64gw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: mongoose&lt;/p&gt;
&lt;p&gt;### Impact
_What kind of vulnerability is it? Who is impacted?_&lt;/p&gt;
&lt;p&gt;Prototype pollution in update casting: passing a user-controlled update to a Mongoose update, like `MyModel.updateOne(filter, req.body)`, can cause Mongoose to set `$fullPath` and `$parentSchemaDocArray` on `Object.prototype`.&lt;/p&gt;
&lt;p&gt;Example:&lt;/p&gt;
&lt;p&gt;```javascript
const mongoose = require(&amp;#39;mongoose&amp;#39;);
console.log(&amp;#39;before:&amp;#39;, Object.prototype.$fullPath);            // undefined&lt;/p&gt;
&lt;p&gt;const User = mongoose.model(&amp;#39;User&amp;#39;, new mongoose.Schema({ name: String }));
const malicious = JSON.parse(&amp;#39;{&amp;#34;$set&amp;#34;: {&amp;#34;__proto__.x&amp;#34;: &amp;#34;anything&amp;#34;}}&amp;#39;);   // attacker-controlled update&lt;/p&gt;
&lt;p&gt;const q = User.updateOne({}, {});
try { q._castUpdate(malicious); } catch (e) { /* throws AFTER the pollution side-effect */ }&lt;/p&gt;
&lt;p&gt;console.log(&amp;#39;after :&amp;#39;, Object.prototype.$fullPath);            // &amp;#34;__proto__&amp;#34;
console.log(&amp;#39;enumerable:&amp;#39;, Object.prototype.propertyIsEnumerable(&amp;#39;$fullPath&amp;#39;));  // true
console.log(&amp;#39;fresh {}:&amp;#39;, ({}).$fullPath);                      // &amp;#34;__proto__&amp;#34;
```&lt;/p&gt;
&lt;p&gt;### Patches
_Has the problem been patched? What versions should users upgrade to?_&lt;/p&gt;
&lt;p&gt;9.7.2, 8.24.1. 7.8.10, 6.13.10&lt;/p&gt;
&lt;p&gt;### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_&lt;/p&gt;
&lt;p&gt;Check user-controlled updates for own `__proto__` properties before passing to Mongoose&lt;/p&gt;
&lt;p&gt;### References
_Are there any links users can visit to find out more?_&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: mongoose&lt;/p&gt;
&lt;p&gt;### Impact
_What kind of vulnerability is it? Who is impacted?_&lt;/p&gt;
&lt;p&gt;Prototype pollution in update casting: passing a user-controlled update to a Mongoose update, like `MyModel.updateOne(filter, req.body)`, can cause Mongoose to set `$fullPath` and `$parentSchemaDocArray` on `Object.prototype`.&lt;/p&gt;
&lt;p&gt;Example:&lt;/p&gt;
&lt;p&gt;```javascript
const mongoose = require(&amp;#39;mongoose&amp;#39;);
console.log(&amp;#39;before:&amp;#39;, Object.prototype.$fullPath);            // undefined&lt;/p&gt;
&lt;p&gt;const User = mongoose.model(&amp;#39;User&amp;#39;, new mongoose.Schema({ name: String }));
const malicious = JSON.parse(&amp;#39;{&amp;#34;$set&amp;#34;: {&amp;#34;__proto__.x&amp;#34;: &amp;#34;anything&amp;#34;}}&amp;#39;);   // attacker-controlled update&lt;/p&gt;
&lt;p&gt;const q = User.updateOne({}, {});
try { q._castUpdate(malicious); } catch (e) { /* throws AFTER the pollution side-effect */ }&lt;/p&gt;
&lt;p&gt;console.log(&amp;#39;after :&amp;#39;, Object.prototype.$fullPath);            // &amp;#34;__proto__&amp;#34;
console.log(&amp;#39;enumerable:&amp;#39;, Object.prototype.propertyIsEnumerable(&amp;#39;$fullPath&amp;#39;));  // true
console.log(&amp;#39;fresh {}:&amp;#39;, ({}).$fullPath);                      // &amp;#34;__proto__&amp;#34;
```&lt;/p&gt;
&lt;p&gt;### Patches
_Has the problem been patched? What versions should users upgrade to?_&lt;/p&gt;
&lt;p&gt;9.7.2, 8.24.1. 7.8.10, 6.13.10&lt;/p&gt;
&lt;p&gt;### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_&lt;/p&gt;
&lt;p&gt;Check user-controlled updates for own `__proto__` properties before passing to Mongoose&lt;/p&gt;
&lt;p&gt;### References
_Are there any links users can visit to find out more?_&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-664h-wqgq-64gw</guid>
    </item>
  </channel>
</rss>
