CVE-2026-15699

MEDIUM

spencermountain compromise Public Root API extend.js nlp.extend prototype pollution

Title source: cna
STIX 2.1

Description

A vulnerability was identified in spencermountain compromise up to 14.15.1. Affected is the function nlp.extend of the file src/API/extend.js of the component Public Root API. The manipulation of the argument plugin leads to improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is b4644ab7179700df0607521f61c1ee9b5f78d89d. Applying a patch is the recommended action to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

References (7)

Core 7
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-378246 | spencermountain compromise Public Root API extend.js nlp.extend prototype pollution
https://vuldb.com/vuln/378246
Signature, Permissions Required signature permissions-required
VDB-378246 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/378246/cti
Third Party Advisory third-party-advisory
CVE-2026-15699 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15699
Third Party Advisory third-party-advisory
Submit #856016 | Node.js compromise 14.15.1 Prototype Pollution
https://vuldb.com/submit/856016

Scores

CVSS v3 6.3
EPSS 0.0026
EPSS Percentile 17.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-1321 CWE-94
Status published
Products (2)
spencermountain/compromise 14.15.0
spencermountain/compromise 14.15.1
Published Jul 14, 2026
Tracked Since Jul 14, 2026