{"id":"CVE-2023-3696","aliases":["BIT-mongoose-2023-3696","GHSA-9m93-w8w6-76hh"],"url":"https://o3.security/vulnerability/CVE-2023-3696","summary":"Prototype Pollution in automattic/mongoose","details":"Prototype Pollution in GitHub repository automattic/mongoose prior to 7.3.4.","published":"2023-07-17T00:00:21.160Z","modified":"2026-07-15T01:49:06.078065063Z","cvss":{"score":10,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"mongoose","fixedVersion":"7.3.3"},{"ecosystem":"npm","name":"mongoose","fixedVersion":"6.11.3"},{"ecosystem":"npm","name":"mongoose","fixedVersion":"5.13.20"}],"fix":{"url":"https://github.com/automattic/mongoose/commit/305ce4ff789261df7e3f6e72363d0703e025f80d","label":"automattic/mongoose@305ce4f"},"references":[{"type":"WEB","url":"https://huntr.dev/bounties/1eef5a72-f6ab-4f61-b31d-fc66f5b4b467"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/3xxx/CVE-2023-3696.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-3696"},{"type":"FIX","url":"https://github.com/automattic/mongoose/commit/305ce4ff789261df7e3f6e72363d0703e025f80d"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:06.078065063Z"}}