CVE-2026-16266

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
21/07/2026
Last modified:
23/07/2026

Description

Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js. An attacker can modify the JavaScript prototype chain by supplying a crafted property path containing special keys such as __proto__.