8.0.13
The MongoDB Ruby team is pleased to announce version 8.0.13 of the mongoid gem - a Ruby ODM for MongoDB. This is a new patch release in the 8.0.x series of Mongoid.
Install this release using RubyGems via the command line as follows:
gem install -v 8.0.13 mongoid
Or simply add it to your Gemfile:
gem 'mongoid', '8.0.13'
Have any feedback? Click on through to MongoDB's Jira and open a new ticket to let us know what's on your mind.
Bug Fixes
Bound regular-expression execution time in in-memory queries (MONGOID-5981) (CVE-2026-93761)
Queries evaluated in memory, such as those against embedded associations, run in the calling thread and can spend an unbounded amount of CPU matching regular expressions. A single in-memory query is now limited by Mongoid.in_memory_regexp_time_limit (default 5.0 seconds); exceeding the limit raises Mongoid::Errors::InMemoryRegexpTimeout.
Resolve nested attribute ids within the caller's association (MONGOID-5992) (CVE-2026-93758)
An id given in nested attributes is now resolved within the association the attributes are being applied to, rather than falling back to a collection-wide lookup that ignored default scopes. A document that is not part of that association raises Mongoid::Errors::DocumentNotFound, and a request to destroy a document that is not in the association is ignored. The new Mongoid.allow_reparenting_via_nested_attributes option (default false) restores the previous reparenting behavior when set to true.
Reject the string form of where under the query operator guard (MONGOID-5993) (
A String passed to #where is sent to MongoDB as a $where expression. This now raises Mongoid::Errors::InvalidQuery when Mongoid.allow_unsafe_query_operators is false (the default); the string form is allowed only when that option is enabled.
Reject JavaScript query operators at any depth (MONGOID-5994) (CVE-2026-93760)
Mongoid.allow_unsafe_query_operators now defaults to false. When it is false, the $where, $function, and $accumulator operators are rejected anywhere in a query selector. The guard covers every criterion-building method (where, find_by, or, and, nor, not, any_of, none_of, and elem_match, including chained operator overrides) and inspects nested expressions such as {'$expr' => {'$function' => ...}} in full.
Other Bug Fixes
- In-memory queries, such as those executed against embedded associations, now read field names from the query as data rather than dispatching them as method calls on the document (MONGOID-5973) (CVE-2026-93762) (CVE-2026-93765)