CVE-2026-16150

A vulnerability was found in RobinHerbots Inputmask up to 5.0.9. Affected by this issue is the function extendDefaults/extendDefinitions/extendAliases in the library lib/dependencyLibs/extend.js of the component Internal Deep Merge Helper. The manipulation results in improperly controlled modification of object prototype attributes. The attack may be performed from remote. The project was informed of the problem early through an issue report but has not responded yet.
Configurations

No configuration.

History

20 Jul 2026, 16:16

Type Values Removed Values Added
References () https://github.com/RobinHerbots/Inputmask/issues/2885 - () https://github.com/RobinHerbots/Inputmask/issues/2885 -

18 Jul 2026, 20:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-18 20:17

Updated : 2026-07-20 16:16


NVD link : CVE-2026-16150

Mitre link : CVE-2026-16150

CVE.ORG link : CVE-2026-16150


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')