CVE-2025-23061

CriticalHigh RiskPatched

Mongoose before 8.9.5 can improperly use a nested $where ...

CVSS Score

9.0

Severity

Critical

Exploit Intelligence

Weaponized

Yes

Detectable

Yes

CISA KEV

Not Listed

Risk Level

High Risk

Detection Sources

osvnuclei

Exploit Sources

github_poc

Get the Full Explanation

Sign in to get the plain English explanation including what systems are affected, how to fix it, and vendor advisory links.

Published: 1/15/2025