- Advisory: GHSA-xqcp-72qc-36p2 · CVE-2026-45621
- Severity: High · CWE-94/CWE-116
- Status: publicly disclosed and fixed. Reported by Pig-Tail through coordinated disclosure.
MongoDB inventory module allows JavaScript injection via unescaped login credential field in generated mongo shell script
Write-up only. No standalone runnable PoC is published for this finding here — refer to the linked advisory for full technical detail, affected range, and the fixed version.