PT-2026-58064 · Git+1 · Mingo

·

CVE-2026-15698

·

Published

2026-07-14

·

Updated

2026-07-14

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions kofrasa mingo versions prior to 7.2.2
Description An issue exists in the Update API component where manipulating the Set argument within the update(), updateOne(), and updateMany() functions can lead to improperly controlled modification of object prototype attributes. This condition allows for a remote attack.
Recommendations Upgrade to version 7.2.2.

Exploit

Fix

Prototype Pollution

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15698

Affected Products

Mingo