← Vulnerability feed

Vulnerability record · CVE-2019-10758 · published 24 December 2019

CVE-2019-10758: mongo-express toBSON endpoint code injection enables RCE

MMongo Express Project · Mongo Express

mongo-express before 0.54.0 misuses the vm dependency to run exec commands in a non-safe environment, allowing code injection through endpoints that call the toBSON method. Because mongo-express is a web admin interface for MongoDB, a successful attack can compromise the database management layer itself.

9.9 CVSS 3.1 Critical CISA KEV since 10 Dec 2021 EPSS 85% · top 0.3% CWE-94 · Code injection
9.9CVSS 3.1 base score, v2 9.0
85%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.9, CISA KEV listing, and very high EPSS probability indicate active exploitation risk with severe impact.

What it is

mongo-express before 0.54.0 misuses the vm dependency to run exec commands in a non-safe environment, allowing code injection through endpoints that call the toBSON method. Because mongo-express is a web admin interface for MongoDB, a successful attack can compromise the database management layer itself.

Impact

An attacker can execute arbitrary code on the host running mongo-express, gaining control of the application and potentially the MongoDB instance it manages. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.

Attack surface

Reached over the network via HTTP requests to mongo-express endpoints that invoke toBSON; the CVSS vector requires low privileges (PR:L) and no user interaction (UI:N).

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2021-12-10, and EPSS shows a 30-day probability of 0.847 (99.7th percentile); reference tags include Exploit, indicating public exploit material exists.

What to do

  • Upgrade mongo-express to 0.54.0 or later, per vendor instructions.
  • Restrict network access to the mongo-express admin interface to trusted management networks only.
  • Do not expose mongo-express directly to the internet; place it behind authentication and a reverse proxy.
  • Run mongo-express with least-privilege OS and MongoDB credentials to limit post-exploitation impact.
  • Monitor for and remove any unauthorized mongo-express deployments in your environment.

Detection

  • Inspect mongo-express HTTP request logs for requests to endpoints that invoke toBSON, especially with unusual or encoded payloads.
  • Monitor process creation on hosts running mongo-express for unexpected child processes such as shells or interpreters spawned by Node.js.
  • Alert on outbound network connections from mongo-express hosts to unfamiliar destinations, which may indicate post-exploitation activity.
  • Check for unexpected changes to mongo-express configuration or files that could indicate tampering.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-10758 to the Known Exploited Vulnerabilities catalog on 10 December 2021 as "MongoDB mongo-express Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 10 June 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-10758 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2019-10758), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.