Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
No PoCs from references.
- https://github.com/ARPSyndicate/cve-scores
- https://github.com/Gokul-Krishnan-V-R/CVE-2024-53900
- https://github.com/NamhyeonKo/mongoose-cve-lab
- https://github.com/plzheheplztrying/cve_monitor
- https://github.com/www-spam/CVE-2024-53900