
CVE-2025-14847 MongoDB Memory Leak Exploit
mongoExploit is a Proof-of-Concept (PoC) exploit tool for CVE-2025-14847, a memory leak vulnerability in MongoDB.
This tool exploits a bug in zlib decompression to leak server memory via BSON field names. By crafting a BSON payload with an inflated document length, it forces the server to read field names from leaked memory until a null byte is encountered.
This tool is for educational and authorized security testing purposes only. The author is not responsible for any misuse of this tool. Do not use this against systems you do not have explicit permission to test.
python3 mongoExploit.py [options]
| Argument | Description | Default |
|---|---|---|
--host | Target host IP or hostname | localhost |
--port | Target MongoDB port | 27017 |
--min-offset | Minimum document length (offset start) | 20 |
--max-offset | Maximum document length (offset end) | 8192 |
--output | Output file for leaked data | leaked.bin |
Scan specific target with default settings:
python3 mongoExploit.py --host 192.168.1.10
Scan for more data with a larger offset range:
python3 mongoExploit.py --host 192.168.1.10 --max-offset 50000
Scan a specific range of offsets:
python3 mongoExploit.py --host 192.168.1.10 --min-offset 100 --max-offset 20000
The tool displays interesting leaks (strings > 10 chars) in the console and saves all collected unique fragments to the specified output file (default: leaked.bin).
It also attempts to highlight patterns resembling secrets such as:
passwordsecretkeytokenadminAKIA (AWS Keys)