← volver
CVE-2026-15598mediumCWE-1321CWE-94

antv layout object.js setNestedValue prototype pollution

33Vexday Risk Score

Sin señal de explotación. Ella tiene prueba de concepto pública.

ssvc Attendcvss 5.3epss 0.3%
de la publicación al arma28 días
Publicada en NVD13 jul
1ª PoC+28d
probabilidad de explotación
0.3%top 76% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
A weakness has been identified in antv layout 2.0.0. This impacts the function setNestedValue in the library lib/util/object.js. Executing a manipulation of the argument path can lead to improperly controlled modification of object prototype attributes. The attack can be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
Productos afectados
antv · layout
PoCs públicas encontradas1
githubgithub.com/IamDremig/CVE-2026-155981
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.