Package compatibility

Mongoose 6.0

What Node.js versions does this Mongoose version support?

Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.

Declared Node.js requirement

engines.node
>=12.0.0
Tip version
6.10.0
Source
npm Registry (engines.node)

Node.js compatibility matrix

Evaluated against CompatHub Node.js VersionLines. Compatibility and lifecycle status are separate signals.

Other Mongoose lines

Security

Advisories affecting Mongoose 6.0 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.

Known vulnerabilities
3
Known exploited
0
Highest CVSS
  • CVE-2026-73562GHSA-664h-wqgq-64gw

    Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)

    Affected:
    <6.13.10
    Fixed in:
    6.13.10
    Source:
    OSV source
  • CVE-2026-42334GHSA-wpg9-53fq-2r8h

    Mongoose's Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection

    Affected:
    <6.13.9
    Fixed in:
    6.13.9
    Source:
    OSV source · Advisory
  • CVE-2025-23061GHSA-vg7j-7cwx-8wgw

    Mongoose search injection vulnerability

    Affected:
    <6.13.6
    Fixed in:
    6.13.6
    Source:
    OSV source · Advisory