Package compatibility

Mongoose 3.5

What Node.js versions does this Mongoose version support?

Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.

Declared Node.js requirement

engines.node
>=0.6.19
Tip version
3.9.7
Source
npm Registry (engines.node)

Node.js compatibility matrix

Evaluated against CompatHub Node.js VersionLines. Compatibility and lifecycle status are separate signals.

Other Mongoose lines

Security

Advisories affecting Mongoose 3.5 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.

Known vulnerabilities
7
Known exploited
0
Highest CVSS
  • CVE-2026-73562GHSA-664h-wqgq-64gw

    Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)

    Affected:
    <6.13.10
    Fixed in:
    6.13.10
    Source:
    OSV source
  • CVE-2026-42334GHSA-wpg9-53fq-2r8h

    Mongoose's Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection

    Affected:
    <6.13.9
    Fixed in:
    6.13.9
    Source:
    OSV source · Advisory
  • CVE-2025-23061GHSA-vg7j-7cwx-8wgw

    Mongoose search injection vulnerability

    Affected:
    <6.13.6
    Fixed in:
    6.13.6
    Source:
    OSV source · Advisory
  • CVE-2023-3696GHSA-9m93-w8w6-76hh

    Mongoose Prototype Pollution vulnerability

    Affected:
    <5.13.20
    Fixed in:
    5.13.20
    Source:
    OSV source · Advisory
  • CVE-2022-24304GHSA-h8hf-x3f4-xwgp

    Mongoose Vulnerable to Prototype Pollution in Schema Object

    Affected:
    <5.13.15
    Fixed in:
    5.13.15
    Source:
    OSV source · Advisory
  • CVE-2022-2564GHSA-f825-f98c-gj3g

    automattic/mongoose vulnerable to Prototype pollution via Schema.path

    Affected:
    <5.13.15
    Fixed in:
    5.13.15
    Source:
    OSV source · Advisory
  • CVE-2019-17426GHSA-8687-vv9j-hgph

    Improper Input Validation in Automattic Mongoose

    Affected:
    <4.13.21
    Fixed in:
    4.13.21
    Source:
    OSV source · Advisory