mongoose
mongoose (latest known version: 9.8.0) has 5 known breaking changes on record, each backed by a source URL.
Security advisories
Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)
Improper Input Validation in Automattic Mongoose
Mongoose Prototype Pollution vulnerability
automattic/mongoose vulnerable to Prototype pollution via Schema.path
Mongoose Vulnerable to Prototype Pollution in Schema Object
Mongoose search injection vulnerability
Remote Memory Exposure in mongoose
Mongoose search injection vulnerability
Mongoose's Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection
Recent changes
Version 9.0.0 is a semver-major release over 8.24.1, but no breaking change was detected in the release notes text - flagged for manual review.
Version 8.0.0 is a semver-major release over 7.8.11, but no breaking change was detected in the release notes text - flagged for manual review.
Version 7.0.0 is a semver-major release over 6.13.9, but no breaking change was detected in the release notes text - flagged for manual review.
Version 6.0.12 is a semver-major release over 4.0.2, but no breaking change was detected in the release notes text - flagged for manual review.
Version 4.0.2 is a semver-major release over 3.8.23, but no breaking change was detected in the release notes text - flagged for manual review.
Check what changed for mongoose since your installed version, live.
Open the playground →