CVE-2026-45325

HIGH

Gestor de Oferta: Prototype pollution in @tmlmobilidade/utils setValueAtPath

Title source: cna
STIX 2.1

Description

Gestor de Oferta is a web application for managing mobility service offerings. Prior to 20260509.0340.15, @tmlmobilidade/utils has a prototype pollution vulnerability in setValueAtPath() in packages/utils/src/generic/value-at-path.ts because unsafe path segments are not blocked. This issue is fixed in version 20260509.0340.15.

Scores

CVSS v3 8.2
EPSS 0.0027
EPSS Percentile 18.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-1321
Status published
Products (1)
tmlmobilidade/go < 20260509.0340.15
Published Jul 16, 2026
Tracked Since Jul 16, 2026