sagold json-schema-library propertyDependencies.ts parsePropertyDependencies prototype pollution
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.3epss 0.3%
probabilidad de explotación
0.3%top 82% de las CVE
explotación observada
noninguna fuente lo reporta
A security vulnerability has been detected in sagold json-schema-library 11.5.0/11.5.1. This impacts the function parsePropertyDependencies of the file src/keywords/propertyDependencies.ts. The manipulation leads to improperly controlled modification of object prototype attributes. The attack can be initiated remotely. Upgrading to version 11.6.0 will fix this issue. The identifier of the patch is 432287ee6f68a02ce6f015354618486ec427a32d. It is advisable to upgrade the affected component.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Productos afectados
sagold · json-schema-libraryReferencias
https://github.com/sagold/json-schema-library/https://github.com/sagold/json-schema-library/commit/432287ee6f68a02ce6f015354618486ec427a32dhttps://github.com/sagold/json-schema-library/issues/111https://github.com/sagold/json-schema-library/releases/tag/v11.6.0https://vuldb.com/cve/CVE-2026-16008https://vuldb.com/submit/856721https://vuldb.com/vuln/379752https://vuldb.com/vuln/379752/cti