eslint-plugin-mongodb-security
NoSQL injection, operator attacks, and MongoDB/Mongoose security rules
AI-Optimized Security
Every rule includes CWE, OWASP, and CVSS metadata for AI assistants to provide precise, context-aware fixes.
Install
npm install -D eslint-plugin-mongodb-securityRules (16)
Browse all MongoDB security rules with CWE/OWASP mapping
Changelog
View version history and updates
Live from GitHub
This content is fetched directly from README.md on GitHub and cached for 1 hour.
β If this plugin caught a real bug for you, star the repo β it's the signal that keeps these rules maintained.
Description
This plugin provides Security rules for MongoDB queries and interactions (NoSQL injection).
- Why β a linter nobody reads protects nothing. We would rather miss a finding than spend your attention on one that was never real.
- How β evidence, not names. A rule fires on what the code does, resolved through the AST and ESLint's own scope analysis.
- What β every finding carries its fix, in prose for a human and as structured JSON for an agent. Security rules add a CWE mapping and, where assigned, a CVSS score.
That trade costs recall, and we measure it: methodology Β· results Β· a false positive is a bug.
Getting Started
- To check out the guide, visit eslint.interlace.tools. π
npm install eslint-plugin-mongodb-security --save-devβοΈ Configuration Presets
| Preset | Description |
|---|---|
recommended | Critical rules as errors, high as warnings |
strict | All rules as errors |
mongoose | Specialized rules for Mongoose ODM usage patterns |
π Supported Libraries
π’ Usage Examples
Prevent NoSQL Injection (no-operator-injection)
// β Incorrect (Vulnerable to { $ne: null })
User.findOne({ email: req.body.email, password: req.body.password });
// β
Correct (Safe execution)
User.findOne({ email: { $eq: email }, password: { $eq: password } });Prevent JavaScript Injection (no-unsafe-where)
// β Incorrect (Allows RCE)
User.find({ $where: `this.name === '${userInput}'` });
// β
Correct (Standard operators)
User.find({ name: { $eq: sanitize(userInput) } });π¦ Compatibility
| Package | Version |
|---|---|
| ESLint | ^8.40.0 || ^9.0.0 || ^10.0.0 |
| Node.js | >=18.0.0 |
See the ESLint Version Support Policy β current ecosystem share data, the 20% gate, and the forward-looking exception that covers v10.
Rules
Legend
| Icon | Description |
|---|---|
| πΌ | Recommended: Included in the recommended preset. |
| β οΈ | Warns: Set to warn in recommended preset. |
| π§ | Auto-fixable: Automatically fixable by the --fix CLI option. |
| π‘ | Suggestions: Providing code suggestions in IDE. |
| π« | Deprecated: This rule is deprecated. |
| π’ | Type-unaware: AST-only, runs in oxlint JS-plugin tier. |
| π‘ | Type-aware (refining): pure-AST primary path; types refine precision. |
| π | Type-aware (graceful): requires TS program; silent without it. |
| Rule | CWE | OWASP | CVSS | Description | π§ | πΌ | β οΈ | π§ | π‘ | π« |
|---|---|---|---|---|---|---|---|---|---|---|
| no-bypass-middleware | CWE-284 | A01:2021 | Detects Mongoose operations that bypass middleware hooks (pre/post hooks). | π’ | β οΈ | |||||
| no-debug-mode-production | CWE-489 | A05:2021 | Detects Mongoose debug mode that could expose sensitive query information in production. | π’ | πΌ | π‘ | ||||
| no-hardcoded-connection-string | CWE-798 | A07:2021 | Detects hardcoded MongoDB connection strings containing credentials in source code. | π’ | πΌ | |||||
| no-hardcoded-credentials | CWE-798 | A07:2021 | Detects hardcoded MongoDB authentication credentials in connection options. | π’ | πΌ | |||||
| no-operator-injection | CWE-943 | A03:2021 | Detects MongoDB operator injection attacks where user input is passed directly as query values, allowing atβ¦ | π’ | πΌ | |||||
| no-select-sensitive-fields | CWE-200 | A01:2021 | Detects queries that may return sensitive fields like passwords, tokens, or API keys. | π’ | β οΈ | |||||
| no-unbounded-find | CWE-400 | A04:2021 | Requires limit() on find queries to prevent resource exhaustion from unbounded result sets. | π’ | β οΈ | π‘ | ||||
| no-unsafe-populate | CWE-943 | A03:2021 | Detects user-controlled populate() paths that could lead to data exposure or injection. | π’ | πΌ | |||||
| no-unsafe-query | CWE-943 | A03:2021 | Prevents NoSQL injection by detecting direct use of user input in MongoDB query objects. | π’ | πΌ | π‘ | ||||
| no-unsafe-regex-query | CWE-400 | A03:2021 | Detects user input in MongoDB $regex operators that could cause ReDoS (Regular Expression Denial of Serviceβ¦ | π’ | πΌ | |||||
| no-unsafe-where | CWE-943 | A01:2021 | Prevents use of the dangerous $where operator which executes JavaScript on the MongoDB server, enabling Remβ¦ | π’ | πΌ | |||||
| require-auth-mechanism | CWE-287 | A07:2021 | Requires explicit authentication mechanism specification for MongoDB connections. | π’ | β οΈ | |||||
| require-lean-queries | CWE-400 | A04:2021 | Suggests using .lean() for read-only Mongoose queries to reduce memory usage. | π’ | π‘ | |||||
| require-projection | CWE-200 | A01:2021 | Requires field projection on queries to minimize data exposure. | π’ | ||||||
| require-schema-validation | CWE-20 | A04:2021 | Requires validation options on Mongoose schema fields to prevent invalid or malicious data. | π’ | β οΈ | |||||
| require-tls-connection | CWE-295 | A02:2021 | Requires TLS/SSL encryption for MongoDB connections in production environments. | π’ | β οΈ | π‘ |
π Related ESLint Plugins
Part of the Interlace ESLint ecosystem β AI-native rules with LLM-optimized error messages:
Security
Code quality
| Plugin | Downloads | Description |
|---|---|---|
eslint-plugin-conventions | Team-specific habits and styles. | |
eslint-plugin-import-next | Fast cycle + import-graph analysis. | |
eslint-plugin-maintainability | Cognitive load and clean-code patterns. | |
eslint-plugin-modernization | ESNext migration + syntax evolution. | |
eslint-plugin-modularity | Structural integrity and DDD patterns. | |
eslint-plugin-operability | Production readiness and resource health. | |
eslint-plugin-react-a11y | React accessibility / WCAG. | |
eslint-plugin-react-features | React best practices and optimization. | |
eslint-plugin-reliability | Runtime stability and error safety. |
β Support & follow
If this plugin caught a real bug for you, star the repo β stars are the signal that keeps the Interlace ESLint ecosystem maintained β and follow the writeups on Dev.to for the benchmarks and security research behind these rules.
π License
MIT Β© Ofri Peretz
View README.md on GitHub β
Building secure JavaScript with Interlace? Star the repo to get new rules and CWE coverage as we ship them β or follow the AI-code-security benchmarks behind them.