Arbitrary command execution via shell-expanded connection string in Launch MongoDB Shell terminal (CVE-2026-84967)
A vulnerability in the MongoDB extension for Visual Studio Code allows an unauthenticated remote attacker to execute arbitrary commands via a specially crafted connection string. The extension fails to neutralize special characters in the connection string before embedding it into a shell command line for the integrated terminal. Exploitation requires user interaction, including accepting a user-supplied connection target and opening the shell feature. The confirmation prompt does not reveal the malicious input. This issue affects versions from 1.13.0 up to but not including 1.17.1. A patch is available to address this vulnerability.
AI Analysis
Technical Summary
The MongoDB extension for Visual Studio Code contains a command injection vulnerability (CVE-2026-84967) due to improper sanitization of special characters in a connection string. When the extension constructs a command line for its integrated terminal shell feature, it inserts the connection string without neutralizing shell metacharacters. An unauthenticated attacker can trick a developer into accepting a malicious connection string and opening the shell, leading to arbitrary command execution on the developer's machine. No privileges are required on the developer's system, but multiple user actions are necessary. The confirmation dialog does not display the injected content, increasing the risk of unnoticed exploitation. The vulnerability affects versions >=1.13.0 and <1.17.1. A patch is available to fix this issue.
Potential Impact
Successful exploitation allows an unauthenticated remote attacker to execute arbitrary commands on a developer's machine via the MongoDB extension's shell feature in Visual Studio Code. This could lead to compromise of the developer's environment. However, exploitation requires social engineering to convince the developer to accept a malicious connection string and open the shell feature. There is no indication of active exploitation in the wild.
Mitigation Recommendations
A patch is available for this vulnerability; users should upgrade the MongoDB extension for Visual Studio Code to version 1.17.1 or later. Until patched, developers should avoid accepting untrusted connection strings and refrain from opening the shell feature with user-supplied connection targets. The vendor advisory should be consulted for the official fix and update instructions.
Arbitrary command execution via shell-expanded connection string in Launch MongoDB Shell terminal (CVE-2026-84967)
Description
A vulnerability in the MongoDB extension for Visual Studio Code allows an unauthenticated remote attacker to execute arbitrary commands via a specially crafted connection string. The extension fails to neutralize special characters in the connection string before embedding it into a shell command line for the integrated terminal. Exploitation requires user interaction, including accepting a user-supplied connection target and opening the shell feature. The confirmation prompt does not reveal the malicious input. This issue affects versions from 1.13.0 up to but not including 1.17.1. A patch is available to address this vulnerability.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The MongoDB extension for Visual Studio Code contains a command injection vulnerability (CVE-2026-84967) due to improper sanitization of special characters in a connection string. When the extension constructs a command line for its integrated terminal shell feature, it inserts the connection string without neutralizing shell metacharacters. An unauthenticated attacker can trick a developer into accepting a malicious connection string and opening the shell, leading to arbitrary command execution on the developer's machine. No privileges are required on the developer's system, but multiple user actions are necessary. The confirmation dialog does not display the injected content, increasing the risk of unnoticed exploitation. The vulnerability affects versions >=1.13.0 and <1.17.1. A patch is available to fix this issue.
Potential Impact
Successful exploitation allows an unauthenticated remote attacker to execute arbitrary commands on a developer's machine via the MongoDB extension's shell feature in Visual Studio Code. This could lead to compromise of the developer's environment. However, exploitation requires social engineering to convince the developer to accept a malicious connection string and open the shell feature. There is no indication of active exploitation in the wild.
Mitigation Recommendations
A patch is available for this vulnerability; users should upgrade the MongoDB extension for Visual Studio Code to version 1.17.1 or later. Until patched, developers should avoid accepting untrusted connection strings and refrain from opening the shell feature with user-supplied connection targets. The vendor advisory should be consulted for the official fix and update instructions.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BIT-mongodb-2026-84967
- Osv Schema Version
- 1.6.2
- Aliases
- ["CVE-2026-84967"]
- Ecosystems
- ["Bitnami"]
- Database Specific Severity
- Medium
Threat ID: 6aa2af68acd9273b4925a7ea
Added to database: 09/10/2026, 13:23:52 UTC
Last enriched: 09/10/2026, 13:30:14 UTC
Last updated: 09/11/2026, 07:31:55 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.