PT-2026-57921 · Git+1 · Db

·

CVE-2026-15607

·

Published

2026-07-13

·

Updated

2026-07-13

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions tanstack db versions prior to 0.6.9
Description A remote attack is possible through the Alias Path Handler component. The select() function in the src/query/compiler/select.ts file allows for the improperly controlled modification of object prototype attributes, a condition known as prototype pollution.
Recommendations Apply patch ac09b1177a100eafa85cba3cd09dd1f53f933ded to remediate the issue.

Exploit

Fix

Prototype Pollution

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15607

Affected Products

Db