CVE-2026-15195: Prototype Pollution in json-schema-ref-parser ≤15.3.5
A prototype pollution vulnerability has been identified in the apidevtools json-schema-ref-parser library (versions up to 15.3.5). The flaw allows authenticated attackers to improperly modify object prototype attributes through the Refs.set and Pointer.set functions. This can be exploited remotely and may lead to unauthorized data modification or application behavior changes. Upgrading to version 15.3.6 resolves the issue.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 6.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Weaknesses (CWE)
- CWE-1321, CWE-94
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-07-09 / 2026-07-09
NVD description (verbatim)
A weakness has been identified in apidevtools json-schema-ref-parser up to 15.3.5. This impacts the function Refs.set/Pointer.set in the library lib/pointer.ts. Executing a manipulation can lead to improperly controlled modification of object prototype attributes. The attack can be launched remotely. Upgrading to version 15.3.6 will fix this issue. This patch is called a786bc6afc3674f650496472ee93d5cf74c4bd84. It is suggested to upgrade the affected component.
9 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-15195 is a prototype pollution weakness in json-schema-ref-parser affecting the lib/pointer.ts module. The vulnerability resides in the Refs.set and Pointer.set functions, which fail to properly sanitize or validate prototype-related object modifications. An authenticated remote attacker can craft malicious input to manipulate object prototypes, potentially affecting the integrity of runtime object properties across the affected application. The vulnerability is mitigated by patch a786bc6afc3674f650496472ee93d5cf74c4bd84, released in version 15.3.6.
Business impact
Prototype pollution vulnerabilities can allow attackers to modify core object behavior in JavaScript applications, potentially leading to privilege escalation, data tampering, or logic bypass. In the context of json-schema-ref-parser, this could compromise the integrity of schema validation and reference resolution, affecting downstream applications that rely on this library for API contract enforcement or configuration parsing. While the CVSS score is MEDIUM, organizations using this library in security-sensitive workflows should prioritize patching.
Affected systems
Applications and services that depend on apidevtools json-schema-ref-parser versions up to and including 15.3.5 are affected. This includes development tools, API gateway configurations, and backend services that use this library for OpenAPI/JSON Schema parsing and validation. The vulnerability requires authentication to exploit, limiting exposure to authenticated users or internal processes.
Exploitability
The vulnerability requires authentication (PR:L per CVSS vector) and network access, making it moderately exploitable. The attack complexity is low (AC:L), meaning no special techniques or timing conditions are required once an attacker has valid credentials. Remote exploitation is possible without user interaction, making this a concern for multi-tenant environments or systems where authentication can be compromised or easily obtained.
Remediation
Organizations should upgrade json-schema-ref-parser to version 15.3.6 or later as soon as practicable. This is a straightforward dependency update in most package management systems (npm, yarn, etc.). Testing should focus on schema validation workflows to ensure the patch does not introduce compatibility issues. For applications unable to upgrade immediately, implement network-level restrictions limiting authentication to trusted IP ranges and monitor for suspicious prototype pollution attempts.
Patch guidance
Upgrade json-schema-ref-parser from affected versions (up to 15.3.5) to 15.3.6 or later. Most projects manage this dependency via npm or yarn; update package.json and run install/upgrade commands. Verify the patch commit hash (a786bc6afc3674f650496472ee93d5cf74c4bd84) in your dependency tree if building from source. Test dependent functionality to confirm schema validation and reference resolution operate as expected post-upgrade. No breaking changes are anticipated, but validate against your internal test suite.
Detection guidance
Monitor application logs for unusual object property modifications or schema validation anomalies. Inspect requests from authenticated users that include nested prototype keys (e.g., __proto__, constructor, prototype) in schema definitions or reference payloads. Use static analysis tools to identify json-schema-ref-parser usage and version in your codebase. Enable verbose logging in the library if available to catch unexpected prototype mutations. Correlate authentication events with potential payload submissions that target prototype pollution vectors.
Why prioritize this
While the CVSS score is MEDIUM (6.3), this vulnerability warrants prompt patching due to its remote exploitability, low attack complexity, and the widespread use of json-schema-ref-parser in API infrastructure. Prototype pollution vulnerabilities are well-understood and actively researched; public exploits may emerge. The requirement for authentication reduces but does not eliminate risk, especially in multi-tenant or federated environments. Prioritize this against low-complexity, low-impact vulnerabilities, but defer to critical CVEs affecting unauthenticated attack surfaces.
Risk score, explained
CVSS 6.3 reflects a MEDIUM severity vulnerability: network-accessible, low attack complexity, authenticated access required, and impact limited to confidentiality, integrity, and availability within the application's privilege boundary. The score accurately captures the moderate risk; however, contextual factors—library ubiquity, prototype pollution prevalence, and API infrastructure dependency—may warrant elevated internal priority ratings in your risk model.
Frequently asked questions
Does this vulnerability affect applications using json-schema-ref-parser in frontend (browser) environments?
Yes, if the library is bundled or executed client-side. However, the authentication requirement suggests the primary risk vector is server-side or internal tooling. Frontend exposure depends on how authentication is handled in your architecture.
What is prototype pollution and why is it dangerous?
Prototype pollution allows attackers to modify the prototype chain of JavaScript objects, affecting all instances and potentially enabling logic bypass, privilege escalation, or data tampering. In a library like json-schema-ref-parser, it could alter how schemas are validated or references are resolved, impacting security policies enforced by those mechanisms.
Is upgrading to 15.3.6 backward compatible?
The patch is expected to be backward compatible; it addresses a security flaw without altering the intended API. However, verify against your test suite and the vendor advisory to confirm compatibility with your specific usage patterns.
Can this vulnerability be exploited without sending a request to the affected application?
No. Exploitation requires remote network access and valid authentication credentials. Internal processes or systems with weak authentication hygiene are at higher risk than well-segmented, externally-facing services.
This analysis is based on publicly available information and the provided vulnerability description as of the publication date. CVSS scores and CWE classifications are as reported by the source. Organizations should verify patch availability and compatibility with their specific deployments against official vendor advisories. SEC.co makes no warranty regarding exploit availability, active exploitation, or real-world impact. This is an informational resource; security decisions should incorporate your organization's risk model, dependency audit, and change management processes. Source: NVD (public-domain), retrieved 2026-08-17. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-12208MEDIUMPrototype Pollution in jsonata-js Library—Exploitation and Remediation Guide
- CVE-2026-12209MEDIUMRubyLouvre Avalon Prototype Pollution Vulnerability – Exploitation Active
- CVE-2026-15187MEDIUMPrototype Pollution in Enquirer ≤2.4.1 – Patch Guidance
- CVE-2026-44495HIGHAxios Prototype Pollution Gadget Vulnerability (0.31.0 & 1.15.1)
- CVE-2026-55388HIGHPiscina Prototype Pollution to Remote Code Execution in Worker Threads
- CVE-2026-0414MEDIUMNETGEAR RBE970 Admin Input Validation Flaw
- CVE-2026-10153MEDIUMCross-Site Scripting in westboy CicadasCMS Search Function
- CVE-2026-10173MEDIUMCross-Site Scripting in Orthanc Explorer 2 – Patch Guidance & Detection