PT-2026-56889 · Npm · Json-Schema-Ref-Parser

·

CVE-2026-15195

·

Published

2026-07-09

·

Updated

2026-07-09

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions apidevtools json-schema-ref-parser versions prior to 15.3.6
Description A weakness in the Refs.set/Pointer.set functions within the lib/pointer.ts library allows for the improperly controlled modification of object prototype attributes. This issue can be exploited remotely through manipulation of the affected functions.
Recommendations Upgrade to version 15.3.6.

Exploit

Fix

Code Injection

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15195

Affected Products

Json-Schema-Ref-Parser