A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into a command line the extension composes for an integrated terminal. An unauthenticated remote unauthorized-user who persuades a developer to accept a user-supplied connection target, and then to open the extension's shell feature, can place characters of the unauthorized-user’s choosing into that command line. No privileges on the developer's machine are required, but several user actions are. The confirmation the developer sees does not display the supplied text.
References
| Link | Resource |
|---|---|
| https://jira.mongodb.org/browse/VSCODE-798 | Issue Tracking |
Configurations
History
No history.
Information
Published : 2026-09-03 16:18
Updated : 2026-09-09 19:51
NVD link : CVE-2026-84967
Mitre link : CVE-2026-84967
CVE.ORG link : CVE-2026-84967
JSON object : View
Products Affected
mongodb
- mongodb
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
