CyberRota Analysis
AI-GeneratedThe vulnerability affects the spencermountain compromise up to version 14.15.1, specifically within the nlp.extend function in the Public Root API, where improper control over the plugin argument allows for unauthorized modifications of object prototype attributes. This could lead to remote exploitation, making it critical for users of the affected product to prioritize applying the available patch to mitigate potential security risks. Organizations utilizing this software should act swiftly to ensure their systems are secured against this publicly exploitable vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability was identified in spencermountain compromise up to 14.15.1. Affected is the function nlp.extend of the file src/API/extend.js of the component Public Root API. The manipulation of the argument plugin leads to improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is b4644ab7179700df0607521f61c1ee9b5f78d89d. Applying a patch is the recommended action to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.