Vulnerability record · CVE-2021-21422 · published 21 June 2021
CVE-2021-21422: Mongo-express project mongo-express cross-site scripting vulnerability
MMongo Express Project · Mongo Express
mongo-express is a web-based MongoDB admin interface, written with Node.js and express. 1: As mentioned in this issue: https://github.com/mongo-express/mongo-express/issues/577, when the content of a cell grows larger than supported size, clicking on a row will show full document unescaped, however this needs admin interaction on cell. 2: Data cells identified as media will be rendered as media, without being sanitized. Example of different renders: image, audio, video, etc. As an example of type 1 attack, an unauthorized user who only can send a large amount of data in a field of a document may use a payload with embedded javascript. This could send an export of a collection to the attacker without even an admin knowing. Other types of attacks such as dropping a database\collection are possible.
Description
mongo-express is a web-based MongoDB admin interface, written with Node.js and express. 1: As mentioned in this issue: https://github.com/mongo-express/mongo-express/issues/577, when the content of a cell grows larger than supported size, clicking on a row will show full document unescaped, however this needs admin interaction on cell. 2: Data cells identified as media will be rendered as media, without being sanitized. Example of different renders: image, audio, video, etc. As an example of type 1 attack, an unauthorized user who only can send a large amount of data in a field of a document may use a payload with embedded javascript. This could send an export of a collection to the attacker without even an admin knowing. Other types of attacks such as dropping a database\collection are possible.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/mongo-express/mongo-express/commit/f5e0d4931f856f032f22664b5e5901d5950cfd4b | PatchThird Party Advisory |
| https://github.com/mongo-express/mongo-express/issues/577 | ExploitThird Party Advisory |
| https://github.com/mongo-express/mongo-express/security/advisories/GHSA-7p8h-86p5-wv3p | ExploitThird Party Advisory |
| https://github.com/mongo-express/mongo-express/commit/f5e0d4931f856f032f22664b5e5901d5950cfd4b | PatchThird Party Advisory |
| https://github.com/mongo-express/mongo-express/issues/577 | ExploitThird Party Advisory |
| https://github.com/mongo-express/mongo-express/security/advisories/GHSA-7p8h-86p5-wv3p | ExploitThird Party Advisory |
Track CVE-2021-21422 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-21422), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.