CVE-2026-15699
MEDIUMspencermountain compromise Public Root API extend.js nlp.extend prototype pollution
Title source: cnaDescription
A vulnerability was identified in spencermountain compromise up to 14.15.1. Affected is the function nlp.extend of the file src/API/extend.js of the component Public Root API. The manipulation of the argument plugin leads to improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is b4644ab7179700df0607521f61c1ee9b5f78d89d. Applying a patch is the recommended action to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
References (7)
Core 7
Core References
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-378246 | spencermountain compromise Public Root API extend.js nlp.extend prototype pollution
https://vuldb.com/vuln/378246
Signature, Permissions Required signature
permissions-required
VDB-378246 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/378246/cti
Third Party Advisory third-party-advisory
CVE-2026-15699 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15699
Third Party Advisory third-party-advisory
Submit #856016 | Node.js compromise 14.15.1 Prototype Pollution
https://vuldb.com/submit/856016
Exploit exploit
issue-tracking
https://github.com/spencermountain/compromise/issues/1208
Patch patch
https://github.com/spencermountain/compromise/commit/b4644ab7179700df0607521f61c1ee9b5f78d89d
Product product
https://github.com/spencermountain/compromise/
Scores
CVSS v3
6.3
EPSS
0.0026
EPSS Percentile
17.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1321
CWE-94
Status
published
Products (2)
spencermountain/compromise
14.15.0
spencermountain/compromise
14.15.1
Published
Jul 14, 2026
Tracked Since
Jul 14, 2026