Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/VSCODE-798 |
|
Thu, 03 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb mongodb For Vs Code |
|
| Vendors & Products |
Mongodb
Mongodb mongodb For Vs Code |
Thu, 03 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into a command line the extension composes for an integrated terminal. An unauthenticated remote unauthorized-user who persuades a developer to accept a user-supplied connection target, and then to open the extension's shell feature, can place characters of the unauthorized-user’s choosing into that command line. No privileges on the developer's machine are required, but several user actions are. The confirmation the developer sees does not display the supplied text. | |
| Title | Arbitrary command execution via shell-expanded connection string in Launch MongoDB Shell terminal | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-09-03T15:30:54.635Z
Reserved: 2026-09-02T17:58:52.742Z
Link: CVE-2026-84967
No data.
Status : Awaiting Analysis
Published: 2026-09-03T16:18:25.703
Modified: 2026-09-03T16:25:43.557
Link: CVE-2026-84967
No data.
OpenCVE Enrichment
Updated: 2026-09-03T16:26:33Z