A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into a command line the extension composes for an integrated terminal. An unauthenticated remote unauthorized-user who persuades a developer to accept a user-supplied connection target, and then to open the extension's shell feature, can place characters of the unauthorized-user’s choosing into that command line. No privileges on the developer's machine are required, but several user actions are. The confirmation the developer sees does not display the supplied text.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/VSCODE-798 |
|
History
Thu, 03 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb mongodb For Vs Code |
|
| Vendors & Products |
Mongodb
Mongodb mongodb For Vs Code |
Thu, 03 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into a command line the extension composes for an integrated terminal. An unauthenticated remote unauthorized-user who persuades a developer to accept a user-supplied connection target, and then to open the extension's shell feature, can place characters of the unauthorized-user’s choosing into that command line. No privileges on the developer's machine are required, but several user actions are. The confirmation the developer sees does not display the supplied text. | |
| Title | Arbitrary command execution via shell-expanded connection string in Launch MongoDB Shell terminal | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published: 2026-09-03T15:18:02.017Z
Updated: 2026-09-03T15:30:54.635Z
Reserved: 2026-09-02T17:58:52.742Z
Link: CVE-2026-84967
Updated: 2026-09-03T15:30:49.753Z
Status : Awaiting Analysis
Published: 2026-09-03T16:18:25.703
Modified: 2026-09-03T16:25:43.557
Link: CVE-2026-84967
No data.