CVE-2026-16266

Summary

Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js. An attacker can modify the JavaScript prototype chain by supplying a crafted property path containing special keys such as proto.

Affected Software

VendorProductVersion RangeStatus
n/amongo-object0 < 3.0.3affected

Weaknesses

  • CWE-1321: Prototype Pollution

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

Additional References

References