Package compatibility

Mongoose 1

What Node.js versions does this Mongoose version support?

Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.

Declared Node.js requirement

engines.node
>= 0.2.0
Tip version
1.8.4
Source
npm Registry (engines.node)

Node.js compatibility matrix

Evaluated against CompatHub Node.js VersionLines. Compatibility and lifecycle status are separate signals.

Other Mongoose lines

Security

Advisories affecting Mongoose 1 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.

Known vulnerabilities
7
Known exploited
0
Highest CVSS
  • CVE-2026-73562GHSA-664h-wqgq-64gw

    Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)

    Affected:
    <6.13.10
    Fixed in:
    6.13.10
    Source:
    OSV source
  • CVE-2026-42334GHSA-wpg9-53fq-2r8h

    Mongoose's Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection

    Affected:
    <6.13.9
    Fixed in:
    6.13.9
    Source:
    OSV source · Advisory
  • CVE-2025-23061GHSA-vg7j-7cwx-8wgw

    Mongoose search injection vulnerability

    Affected:
    <6.13.6
    Fixed in:
    6.13.6
    Source:
    OSV source · Advisory
  • CVE-2023-3696GHSA-9m93-w8w6-76hh

    Mongoose Prototype Pollution vulnerability

    Affected:
    <5.13.20
    Fixed in:
    5.13.20
    Source:
    OSV source · Advisory
  • CVE-2022-24304GHSA-h8hf-x3f4-xwgp

    Mongoose Vulnerable to Prototype Pollution in Schema Object

    Affected:
    <5.13.15
    Fixed in:
    5.13.15
    Source:
    OSV source · Advisory
  • CVE-2022-2564GHSA-f825-f98c-gj3g

    automattic/mongoose vulnerable to Prototype pollution via Schema.path

    Affected:
    <5.13.15
    Fixed in:
    5.13.15
    Source:
    OSV source · Advisory
  • CVE-2019-17426GHSA-8687-vv9j-hgph

    Improper Input Validation in Automattic Mongoose

    Affected:
    <4.13.21
    Fixed in:
    4.13.21
    Source:
    OSV source · Advisory