Live data from GitHub and npm, updated daily.
Data last fetched: 2026-05-15
8 active CVEs reported via OSV.dev
Improper Input Validation in Automattic Mongoose
Mongoose Prototype Pollution vulnerability
automattic/mongoose vulnerable to Prototype pollution via Schema.path
Mongoose Vulnerable to Prototype Pollution in Schema Object
Mongoose search injection vulnerability
Remote Memory Exposure in mongoose
Mongoose search injection vulnerability
Mongoose's Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection
Other Database Tools projects in the Node.js ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for Mongoose โ without relying on volunteer maintainers.
Talk to an Expert โ