Package compatibility
Mongoose 1
What Node.js versions does this Mongoose version support?
Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.
Declared Node.js requirement
- engines.node
- >= 0.2.0
- Tip version
- 1.8.4
- Source
- npm Registry (engines.node)
Node.js compatibility matrix
Evaluated against CompatHub Node.js VersionLines. Compatibility and lifecycle status are separate signals.
Other Mongoose lines
Security
Advisories affecting Mongoose 1 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.
- Known vulnerabilities
- 7
- Known exploited
- 0
- Highest CVSS
- —
- CVE-2026-73562GHSA-664h-wqgq-64gw
Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)
- Affected:
- <6.13.10
- Fixed in:
- 6.13.10
- Source:
- OSV source
- CVE-2026-42334GHSA-wpg9-53fq-2r8h
Mongoose's Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection
- Affected:
- <6.13.9
- Fixed in:
- 6.13.9
- Source:
- OSV source · Advisory
- CVE-2025-23061GHSA-vg7j-7cwx-8wgw
Mongoose search injection vulnerability
- Affected:
- <6.13.6
- Fixed in:
- 6.13.6
- Source:
- OSV source · Advisory
- CVE-2023-3696GHSA-9m93-w8w6-76hh
Mongoose Prototype Pollution vulnerability
- Affected:
- <5.13.20
- Fixed in:
- 5.13.20
- Source:
- OSV source · Advisory
- CVE-2022-24304GHSA-h8hf-x3f4-xwgp
Mongoose Vulnerable to Prototype Pollution in Schema Object
- Affected:
- <5.13.15
- Fixed in:
- 5.13.15
- Source:
- OSV source · Advisory
- CVE-2022-2564GHSA-f825-f98c-gj3g
automattic/mongoose vulnerable to Prototype pollution via Schema.path
- Affected:
- <5.13.15
- Fixed in:
- 5.13.15
- Source:
- OSV source · Advisory
- CVE-2019-17426GHSA-8687-vv9j-hgph
Improper Input Validation in Automattic Mongoose
- Affected:
- <4.13.21
- Fixed in:
- 4.13.21
- Source:
- OSV source · Advisory
