Sploitus

CVE-2025-6713

1 known exploit for CVE-2025-6713

An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server. This may lead to access to data without further authorisation. This issue affects MongoDB Server MongoDB Server v8.0 versions prior to 8.0.7, MongoDB Server v7.0 versions prior to 7.0.19 and MongoDB Server v6.0 versions prior to 6.0.22

Mongodb
< 6.0.22, 7.0.19, 8.0.7
Fix
Available
CVSS 3.1
7.7 HIGH
EPSS
0.3% (27th percentile)
Weakness
CWE-285
NVD status
Analyzed
Published
2025-07-07
CVE-2025-6713 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2025-6713

Proof-of-concept code and exploit modules indexed by Sploitus