CVE-2025-1755 Details
Description
MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1
A local privilege escalation vulnerability has been identified in MongoDB Compass versions prior to 1.42.1. This issue arises when a crafted file is placed in the user's node_modules directory, potentially allowing unauthorized actions to be performed on the user's system with elevated privileges. The vulnerability is specific to Windows environments.
Users can upgrade to MongoDB Compass version 1.42.1 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2025:1755.html | CISA-ADP | Third Party Advisory |
| https://jira.mongodb.org/browse/COMPASS-9058 | [email protected] | Issue TrackingVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-426 | Untrusted Search Path | [email protected] |
| CWE-426 | Untrusted Search Path | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mongodb compass | < 1.42.1 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
| redhat enterprise linux for arm 64 | 9.0_aarch64 |
CPE
Remediation
| |
| redhat enterprise linux for ibm z systems | 9.0_s390x |
CPE
Remediation
| |
| redhat enterprise linux server for power little endian update services for sap solutions | 9.0_ppc64le |
CPE
Remediation
| |
| redhat enterprise linux update services for sap solutions | 9.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 9, 2025 | Initial Analysis | [email protected] |
| Feb 27, 2025 | New CVE Received | [email protected] |
| Feb 27, 2025 | CVE Modified | CISA-ADP |