CVE-2026-15195
A weakness has been identified in apidevtools json-schema-ref-parser up to 15.3.5. This impacts the function Refs.set/Pointer.set in the lib
CVSS
6.3
Medio
EPSS
0.3%
p18
KEV
—
Exploit Today
5
0-100
Publicado: 9 jul 2026 · Última mod.: 9 jul 2026 · CWE-94 · CWE-1321
0.3%EPSS · 30 días0.3%
2026-07-102026-07-21
A weakness has been identified in apidevtools json-schema-ref-parser up to 15.3.5. This impacts the function Refs.set/Pointer.set in the library lib/pointer.ts. Executing a manipulation can lead to improperly controlled modification of object prototype attributes. The attack can be launched remotely. Upgrading to version 15.3.6 will fix this issue. This patch is called a786bc6afc3674f650496472ee93d5cf74c4bd84. It is suggested to upgrade the affected component.
- github.comhttps://github.com/APIDevTools/json-schema-ref-parser/
- github.comhttps://github.com/APIDevTools/json-schema-ref-parser/commit/a786bc6afc3674f650496472ee93d5cf74c4bd84
- github.comhttps://github.com/APIDevTools/json-schema-ref-parser/issues/421
- github.comhttps://github.com/APIDevTools/json-schema-ref-parser/releases/tag/v15.3.6
- vuldb.comhttps://vuldb.com/cve/CVE-2026-15195
- vuldb.comhttps://vuldb.com/submit/851809
- vuldb.comhttps://vuldb.com/vuln/377123
- vuldb.comhttps://vuldb.com/vuln/377123/cti
- github.comhttps://github.com/APIDevTools/json-schema-ref-parser/issues/421
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-650089.8 CRÍ—
——0Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method callable string and its arguments directly to call_user_func_array() without any allowlist. Because the form plugin routes page frontmatter through this path, an authenticated account with the admin.pages (or api.pages.write) permission can plant a malicious callable directive in a page. The command then executes as the web-server user whenever anyone — including an unauthenticated visitor — accesses the page.3hCVE-2026-162664.0 MED16.0%
——5Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js. An attacker can modify the JavaScript prototype chain by supplying a crafted property path containing special keys such as __proto__.10hCVE-2026-535924.6 MED2.1%
——1FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A Prototype Pollution condition in the `getQueryParam` function `/public/js/main.js` and was addressed in version 1.8.139 by blocking URL query keys matching the pattern `__proto__`. However, this mitigation is incomplete: it only filters top-level `__proto__` keys and fails to sanitize nested forms such as `b[__proto__][polluted]=PWNED`. As a result, an attacker-controlled URL query string can still write into `Object.prototype` on any page that loads `main.js`. Version 1.8.223 contains a updated fix.20hCVE-2026-60026—23.3%
——7The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (core.create/core.edit) could inject PHP tags in element content, that got executed via view-cache include(). Requires caching on (default).21hCVE-2026-4435910.0 CRÍ59.1%
——18Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target and multiple jobs check out the attacker's fork code and execute it with access to repository secrets and elevated GITHUB_TOKEN permissions. No approval gate exists. Pull requests from external users with author_association: "NONE" triggered the CI workflow automatically. The workflow directly executes attacker-controlled files from the fork checkout. This issue could have resulted in supply chain compromise, self-hosted runner compromise, and/or repository takeover for the repo. This issue is separate from GHSA-6mwm-v2vv-pp96, which addressed a command injection via github.head_ref in the setup job of the same workflow. That fix correctly moved to environment variables. However, the more critical fork checkout vulnerability across the check, build, and build-debian-src jobs was not addressed. Version 2.7.21.1370b23 contains a patch for thie issue.21hCVE-2026-162294.3 MED35.9%
——11A flaw has been found in itsourcecode Courier Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php. Executing a manipulation of the argument page can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used.1d