Vulnerability Description
Gestor de Oferta is a web application for managing mobility service offerings. Prior to 20260509.0340.15, @tmlmobilidade/utils has a prototype pollution vulnerability in setValueAtPath() in packages/utils/src/generic/value-at-path.ts because unsafe path segments are not blocked. This issue is fixed in version 20260509.0340.15.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/tmlmobilidade/go/commit/b10505baa7ba0701f830a05f3007c0a6bdd00
- https://github.com/tmlmobilidade/go/security/advisories/GHSA-cmxg-94mg-jq94
FAQ
What is CVE-2026-45325?
CVE-2026-45325 is a vulnerability with a CVSS score of 8.2 (HIGH). Gestor de Oferta is a web application for managing mobility service offerings. Prior to 20260509.0340.15, @tmlmobilidade/utils has a prototype pollution vulnerability in setValueAtPath() in packages/u...
How severe is CVE-2026-45325?
CVE-2026-45325 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-45325?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.