CVE-2020-24391 is a critical-severity (CVSS 9.8) vulnerability in mongodb-query-parser. EPSS puts its 30-day exploitation probability at 74.5% (99th percentile). A fix is available for mongodb-query-parser — see the affected versions and patch details below.
Remote code execution in mongo-express
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
CVE-2020-24391 by exploitation likelihood (EPSS) against impact (CVSS). In the shaded patch-first corner (EPSS 50%+, CVSS 7.0+).
Where this sits among everything scored
Of 385,386 CVEs with a current EPSS score, this one falls in the 50–90% band (highlighted). Counts from FIRST.org, log-scaled.
Real-World Exposure
How broadly this vulnerability is actually deployed: weekly install volume shows current usage, a proxy for how much of the ecosystem is exposed.
mongodb-query-parsernpmDescription
mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this may overlap CVE-2019-10769.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 📦npm | mongodb-query-parser | all versions | 2.0.0npm install mongodb-query-parser@2.0.0 |
Affected Products
mongo-expressmongo-express_projectDetection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for mongodb-query-parser, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update mongodb-query-parser to 2.0.0 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2020-24391 is resolved across your whole dependency graph.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
How to detect CVE-2020-24391
A community-maintained Nuclei template exists for this CVE. You can scan for it directly:
nuclei -id cve-2020-24391 -u https://target- Template
- Mongo-Express - Remote Code Execution
- Severity
- critical
- Impact
- Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
- Remediation
- Apply the latest security patches or updates provided by the vendor to fix this vulnerability.
Template by ProjectDiscovery nuclei-templates (leovalcante), MIT licensed. View the full template. Scan only systems you are authorised to test.
Frequently Asked Questions
Is CVE-2020-24391 in your dependencies?
Find it across npm, including transitive dependencies.