CVE-2026-15699

A vulnerability was identified in spencermountain compromise up to 14.15.1. Affected is the function nlp.extend of the file src/API/extend.js of the component Public Root API. The manipulation of the argument plugin leads to improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is b4644ab7179700df0607521f61c1ee9b5f78d89d. Applying a patch is the recommended action to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Configurations

No configuration.

History

14 Jul 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-14 16:16

Updated : 2026-07-14 18:17


NVD link : CVE-2026-15699

Mitre link : CVE-2026-15699

CVE.ORG link : CVE-2026-15699


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')