CVE-2022-2564
9.8
CRITICAL · CVSS 3.1 · EPSS 32.7% (pctl 98)
Patch early
EPSS 32.7% — above the 10% action threshold.
Description
Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 32.68% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-1321 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2022-07-28 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| mongoosejs | mongoose |
References
- https://github.com/Automattic/mongoose/blob/51e758541763b6f14569744ced15cc23ab8b50c6/lib/schema.js#L88-L141
- https://github.com/Automattic/mongoose/compare/6.4.5...6.4.6
- https://github.com/automattic/mongoose/commit/a45cfb6b0ce0067ae9794cfa80f7917e1fb3c6f8
- https://huntr.dev/bounties/055be524-9296-4b2f-b68d-6d5b810d1ddd
- https://github.com/Automattic/mongoose/blob/51e758541763b6f14569744ced15cc23ab8b50c6/lib/schema.js#L88-L141
- https://github.com/Automattic/mongoose/compare/6.4.5...6.4.6
- https://github.com/automattic/mongoose/commit/a45cfb6b0ce0067ae9794cfa80f7917e1fb3c6f8
- https://huntr.dev/bounties/055be524-9296-4b2f-b68d-6d5b810d1ddd
→ the Explorer · watch your stack · NVD