PT-2026-58088 · Git+1 · Compromise

·

CVE-2026-15699

·

Published

2026-07-14

·

Updated

2026-07-14

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions spencermountain compromise versions prior to 14.15.1
Description Remote exploitation is possible through the Public Root API component. The nlp.extend() function in the src/API/extend.js file allows for the improper modification of object prototype attributes when the plugin argument is manipulated. This issue is known as prototype pollution, where an attacker can inject properties into existing object prototypes, potentially altering the behavior of the application.
Recommendations Apply the patch b4644ab7179700df0607521f61c1ee9b5f78d89d to versions prior to 14.15.1. As a temporary mitigation, restrict the use of the nlp.extend() function.

Exploit

Fix

Prototype Pollution

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15699

Affected Products

Compromise