CVE-2026-16266 - mongo-object Prototype Pollution Vulnerability
CVE ID :CVE-2026-16266
Published : July 21, 2026, 6:16 a.m. | 4 hours, 33 minutes ago
Description :Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js. An attacker can modify the JavaScript prototype chain by supplying a crafted property path containing special keys such as __proto__.
Severity: 4.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : July 21, 2026, 6:16 a.m. | 4 hours, 33 minutes ago
Description :Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js. An attacker can modify the JavaScript prototype chain by supplying a crafted property path containing special keys such as __proto__.
Severity: 4.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...