CVE-2026-15195

MEDIUM

apidevtools json-schema-ref-parser pointer.ts Pointer.set prototype pollution

Title source: cna
STIX 2.1

Description

A weakness has been identified in apidevtools json-schema-ref-parser up to 15.3.5. This impacts the function Refs.set/Pointer.set in the library lib/pointer.ts. Executing a manipulation can lead to improperly controlled modification of object prototype attributes. The attack can be launched remotely. Upgrading to version 15.3.6 will fix this issue. This patch is called a786bc6afc3674f650496472ee93d5cf74c4bd84. It is suggested to upgrade the affected component.

References (8)

Core 8
Core References
Signature, Permissions Required signature permissions-required
VDB-377123 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/377123/cti
Vdb Entry, Technical Description vdb-entry technical-description
VDB-377123 | apidevtools json-schema-ref-parser pointer.ts Pointer.set prototype pollution
https://vuldb.com/vuln/377123
Third Party Advisory third-party-advisory
CVE-2026-15195 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15195
Third Party Advisory third-party-advisory
Submit #851809 | Node.js @apidevtools/json-schema-ref-parser 15.3.5 Improperly Controlled Modification of Object Prototype Attribute
https://vuldb.com/submit/851809

Scores

CVSS v3 6.3
EPSS 0.0026
EPSS Percentile 17.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-1321 CWE-94
Status published
Products (7)
apidevtools/json-schema-ref-parser 15.3.0
apidevtools/json-schema-ref-parser 15.3.1
apidevtools/json-schema-ref-parser 15.3.2
apidevtools/json-schema-ref-parser 15.3.3
apidevtools/json-schema-ref-parser 15.3.4
apidevtools/json-schema-ref-parser 15.3.5
apidevtools/json-schema-ref-parser 15.3.6
Published Jul 09, 2026
Tracked Since Jul 09, 2026