← back
CVE-2026-15598mediumCWE-1321CWE-94

antv layout object.js setNestedValue prototype pollution

33Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 5.3epss 0.3%
from disclosure to weapon28 days
Published on NVDJul 13
1st PoC+28d
exploitation probability
0.3%top 76% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A weakness has been identified in antv layout 2.0.0. This impacts the function setNestedValue in the library lib/util/object.js. Executing a manipulation of the argument path can lead to improperly controlled modification of object prototype attributes. The attack can be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
Affected products
antv · layout
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.