THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-73562 (MEDIUM 6.5) — Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.24.1, and 9.7.2, passing a user-controlled update such as MyModel.updateOne(filter, req.body) can exploit Mongoose update casting with a __proto__.x dotted path

[NVD] CVE-2026-73562 (MEDIUM 6.5) — Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.24.1, and 9.7.2, passing a user-controlled update such as MyModel.updateOne(filter, req.body) can exploit Mongoose update casting with a __proto__.x dotted path

lownvdPublished 2026-08-13

CVE-2026-73562 CVSS: 6.5 MEDIUM Published: 2026-08-13T18:18:18.643

Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.24.1, and 9.7.2, passing a user-controlled update such as MyModel.updateOne(filter, req.body) can exploit Mongoose update casting with a __proto__.x dotted path under $set. Schema.prototype.path and Schema.protot

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73562