Skip to content

[GHSA-h47j-hc6x-h3qq] Remote Code Execution Vulnerability in NPM mongo-express #5855

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: JLLeitschuh/advisory-improvement-5855
Choose a base branch
from

Conversation

JLLeitschuh
Copy link

Updates

  • Affected products
  • Description
  • References
  • Source code location

Comments
I was the original reporter of this vulnerability. Wanted to clean up this disclosure just a bit.

@github
Copy link
Collaborator

github commented Jul 25, 2025

Hi there @dozoisch! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository.

This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory

@Copilot Copilot AI review requested due to automatic review settings July 25, 2025 16:29
Copy link

@Copilot Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates a GitHub Security Advisory for a Remote Code Execution vulnerability in NPM mongo-express to improve the disclosure documentation. The changes include adding a reference to the CISA Known Exploited Vulnerabilities list and providing additional source code references.

  • Added mention of CISA KEV status to emphasize vulnerability severity
  • Improved reference formatting and added new reference links
  • Updated modification timestamp

},
{
"type": "PACKAGE",
"url": "https://github.com/mongo-express/mongo-express/blob/ea02b364d43f179f191fc91fb9962efdb0843a8d/lib/bson.js#L60"
Copy link
Preview

Copilot AI Jul 25, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The PACKAGE reference should point to the repository root rather than a specific file and line. Consider using "https://github.com/mongo-express/mongo-express" as the URL for the PACKAGE type reference.

Suggested change
"url": "https://github.com/mongo-express/mongo-express/blob/ea02b364d43f179f191fc91fb9962efdb0843a8d/lib/bson.js#L60"
"url": "https://github.com/mongo-express/mongo-express"

Copilot uses AI. Check for mistakes.

@github-actions github-actions bot changed the base branch from main to JLLeitschuh/advisory-improvement-5855 July 25, 2025 16:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants