
Entorno reproducible y PoC para CVE-2024-53900, un RCE crítico en Mongoose a través de populate().match $where. Incluye script de explotación automatizado y plantilla Nuclei para pruebas de seguridad.
const assert = require('assert');
const $defineProperty = require('es-define-property');
if ($defineProperty) {
assert.equal($defineProperty, Object.defineProperty);
} else if (Object.defineProperty) {
assert.equal($defineProperty, false, 'this is IE 8');
} else {
assert.equal($defineProperty, false, 'this is an ES3 engine');
}
Simply clone the repo, npm install, and run npm test
Please email @ljharb or see https://tidelift.com/security if you have a potential security vulnerability to report.