Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering shell.openExternal after specific user behavior leading to "1-click" command execution.
References
| Link | Resource |
|---|---|
| https://jira.mongodb.org/browse/COMPASS-10657 |
Configurations
No configuration.
History
20 May 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-20 17:16
Updated : 2026-05-20 17:32
NVD link : CVE-2026-9101
Mitre link : CVE-2026-9101
CVE.ORG link : CVE-2026-9101
JSON object : View
Products Affected
No product.
CWE
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
