Improper Data Query Logic in MongoDB Ruby Driver
CVE-2026-88030
6.1MEDIUM
What is CVE-2026-88030?
The MongoDB Ruby Driver contains a security flaw in its GridFS component due to improper handling of special elements in data query logic. This vulnerability allows an authenticated user to manipulate the structured file identifier passed by the application, leading to unintended query interpretations. As a result, the attacker may gain access to stored file content beyond the designated target or potentially delete all file chunks in the affected GridFS bucket. This can render stored file content unreadable, posing a significant security risk.
Affected Version(s)
Ruby Driver 2.0.0 <= 2.25.0