PT-2026-58088 · Git+1 · Compromise
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
spencermountain compromise versions prior to 14.15.1
Description
Remote exploitation is possible through the Public Root API component. The
nlp.extend() function in the src/API/extend.js file allows for the improper modification of object prototype attributes when the plugin argument is manipulated. This issue is known as prototype pollution, where an attacker can inject properties into existing object prototypes, potentially altering the behavior of the application.Recommendations
Apply the patch b4644ab7179700df0607521f61c1ee9b5f78d89d to versions prior to 14.15.1.
As a temporary mitigation, restrict the use of the
nlp.extend() function.Exploit
Fix
Prototype Pollution
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Compromise