mongoose

mongoose breaking-changes badge

mongoose (latest known version: 9.8.0) has 5 known breaking changes on record, each backed by a source URL.

Actively maintainedLatest known version: 9.8.0npm ↗

Security advisories

GHSA-664h-wqgq-64gwMODERATE<6.13.10 || >=7.0.0 <7.8.10 || >=8.0.0 <8.24.1 || >=9.0.0 <9.7.2

Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)

source ↗

GHSA-8687-vv9j-hgphCRITICAL>=5.0.0 <5.7.5 || <4.13.21

Improper Input Validation in Automattic Mongoose

source ↗

GHSA-9m93-w8w6-76hhCRITICAL>=7.0.0 <7.3.3 || >=6.0.0 <6.11.3 || <5.13.20

Mongoose Prototype Pollution vulnerability

source ↗

GHSA-f825-f98c-gj3gHIGH>=6.0.0 <6.4.6 || <5.13.15

automattic/mongoose vulnerable to Prototype pollution via Schema.path

source ↗

GHSA-h8hf-x3f4-xwgpCRITICAL>=6.0.0 <6.4.6 || <5.13.15

Mongoose Vulnerable to Prototype Pollution in Schema Object

source ↗

GHSA-m7xq-9374-9rvxHIGH>=8.0.0-rc0 <8.8.3 || >=7.0.0-rc0 <7.8.3 || >=6.0.0-rc0 <6.13.5 || >=3.6.0-rc0 <5.13.23

Mongoose search injection vulnerability

source ↗

GHSA-r5xw-q988-826mMODERATE>=3.5.5 <3.8.39 || >=4.0.0 <4.3.6

Remote Memory Exposure in mongoose

source ↗

GHSA-vg7j-7cwx-8wgwCRITICAL>=8.0.0-rc0 <8.9.5 || >=7.0.0-rc0 <7.8.4 || <6.13.6

Mongoose search injection vulnerability

source ↗

GHSA-wpg9-53fq-2r8hHIGH<6.13.9 || >=7.0.0 <7.8.9 || >=8.0.0 <8.22.1 || >=9.0.0 <9.1.6

Mongoose's Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection

source ↗

Recent changes

v9.0.0Breaking

Version 9.0.0 is a semver-major release over 8.24.1, but no breaking change was detected in the release notes text - flagged for manual review.

source ↗

v8.0.0Breaking

Version 8.0.0 is a semver-major release over 7.8.11, but no breaking change was detected in the release notes text - flagged for manual review.

source ↗

v7.0.0Breaking

Version 7.0.0 is a semver-major release over 6.13.9, but no breaking change was detected in the release notes text - flagged for manual review.

source ↗

v6.0.12Breaking

Version 6.0.12 is a semver-major release over 4.0.2, but no breaking change was detected in the release notes text - flagged for manual review.

source ↗

v4.0.2Breaking

Version 4.0.2 is a semver-major release over 3.8.23, but no breaking change was detected in the release notes text - flagged for manual review.

source ↗

Check what changed for mongoose since your installed version, live.

Open the playground →