Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-6713— MongoDB Server may be susceptible to privilege escalation due to $mergeCursors stage

CVSS 7.7 · High EPSS 0.32% · P55
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-6713

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MongoDB Server may be susceptible to privilege escalation due to $mergeCursors stage
Source: NVD (National Vulnerability Database)
Vulnerability Description
An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server. This may lead to access to data without further authorisation. This issue affects MongoDB Server MongoDB Server v8.0 versions prior to 8.0.7, MongoDB Server v7.0 versions prior to 7.0.19 and MongoDB Server v6.0 versions prior to 6.0.22
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
授权机制不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
MongoDB Server 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
MongoDB Server是美国MongoDB公司的一套开源的NoSQL数据库。该数据库提供面向集合的存储、动态查询、数据复制及自动故障转移等功能。 MongoDB Server 8.0.7之前版本、7.0.20之前版本和6.0.22之前版本存在安全漏洞,该漏洞源于对$mergeCursors阶段处理不当,可能导致未授权数据访问。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
MongoDB IncMongoDB Server 6.0 ~ 6.0.22 cpe:2.3:a:mongodb:mongodb:6.0.0:*:*:*:*:*:*:*

II. Public POCs for CVE-2025-6713

#POC DescriptionSource LinkShenlong Link
1craft aggregation pipeline to access data without proper authorisation due to improper handling of $mergeCursors in MongoDB >v8.0 <8.0.7, >v7.0 <7.0.19, >v6.0 <6.0.22https://github.com/c137req/CVE-2025-6713POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-6713

登录查看更多情报信息。

Same Patch Batch · MongoDB Inc · 2025-07-07 · 5 CVEs total

CVE-2025-67147.5 HIGHIncorrect Handling of incomplete data may prevent mongoS from Accepting New Connections
CVE-2025-67126.5 MEDIUMMongoDB Server may be susceptible to DoS due to Accumulated Memory Allocation
CVE-2025-72596.5 MEDIUMCertain Queries with Duplicate _id Fields May Cause MongoDB Server to Crash
CVE-2025-67114.4 MEDIUMIncomplete Redaction of Sensitive Information in MongoDB Server Logs

IV. Related Vulnerabilities

V. Comments for CVE-2025-6713

No comments yet


Leave a comment