PT-2026-56889 · Npm · Json-Schema-Ref-Parser
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
apidevtools json-schema-ref-parser versions prior to 15.3.6
Description
A weakness in the
Refs.set/Pointer.set functions within the lib/pointer.ts library allows for the improperly controlled modification of object prototype attributes. This issue can be exploited remotely through manipulation of the affected functions.Recommendations
Upgrade to version 15.3.6.
Exploit
Fix
Code Injection
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Json-Schema-Ref-Parser