CVE-2026-16008

A security vulnerability has been detected in sagold json-schema-library 11.5.0/11.5.1. This impacts the function parsePropertyDependencies of the file src/keywords/propertyDependencies.ts. The manipulation leads to improperly controlled modification of object prototype attributes. The attack can be initiated remotely. Upgrading to version 11.6.0 will fix this issue. The identifier of the patch is 432287ee6f68a02ce6f015354618486ec427a32d. It is advisable to upgrade the affected component.
Configurations

No configuration.

History

17 Jul 2026, 13:17

Type Values Removed Values Added
References () https://github.com/sagold/json-schema-library/issues/111 - () https://github.com/sagold/json-schema-library/issues/111 -

17 Jul 2026, 11:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-17 11:17

Updated : 2026-07-17 14:59


NVD link : CVE-2026-16008

Mitre link : CVE-2026-16008

CVE.ORG link : CVE-2026-16008


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')