PT-2026-58064 · Git+1 · Mingo
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
kofrasa mingo versions prior to 7.2.2
Description
An issue exists in the Update API component where manipulating the
Set argument within the update(), updateOne(), and updateMany() functions can lead to improperly controlled modification of object prototype attributes. This condition allows for a remote attack.Recommendations
Upgrade to version 7.2.2.
Exploit
Fix
Prototype Pollution
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mingo