SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-15195

MEDIUM · CVSS 6.3 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

A vulnerability exists in the apidevtools json-schema-ref-parser library, specifically in the Refs.set/Pointer.set functions within lib/pointer.ts, allowing for remote manipulation that can lead to uncontrolled modifications of object prototype attributes. This could potentially enable an attacker to alter the behavior of applications relying on this library. Developers and organizations utilizing versions up to 15.3.5 should prioritize upgrading to version 15.3.6 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15195
Severity
MEDIUM
CVSS
6.3
EPSS
0.26%

Original NVD Description

A weakness has been identified in apidevtools json-schema-ref-parser up to 15.3.5. This impacts the function Refs.set/Pointer.set in the library lib/pointer.ts. Executing a manipulation can lead to improperly controlled modification of object prototype attributes. The attack can be launched remotely. Upgrading to version 15.3.6 will fix this issue. This patch is called a786bc6afc3674f650496472ee93d5cf74c4bd84. It is suggested to upgrade the affected component.