Hunting Nosql Operator And Where Injection

Hunt NoSQL injection where untrusted input becomes query structure rather than a bound value: a request body whose keys turn into query operators, a value that arrives as an object instead of a scalar, or input reaching a server-side JavaScript evaluation such as $where, a mapReduce function, or an aggregation expression. Covers document stores where a filter built from a request object lets the caller inject comparison operators, always-true conditions, or code, and key-value or wide-column stores where input shapes the query language. Use when data access takes structured input from the request into a query filter or a server-side expression. The untrusted value that becomes an operator or an expression is the source, the query or evaluation call is the sink, and the missing type and shape check is the bug.

UnboundCompute Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/hunting-nosql-operator-and-where-injection commit e8ab6f5982

Frequently asked questions

npx skillmds@latest add unboundcompute/hunting-nosql-operator-and-where-injection