PT-2026-36855 · Evolve · Evolver

Xeloxa

·

Published

2026-04-22

·

Updated

2026-05-04

·

CVE-2026-42077

CVSS v3.1

5.2

Medium

VectorAV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Evolver versions prior to 1.69.3
Description A prototype pollution issue in the mailbox store module allows attackers to modify the behavior of all JavaScript objects by injecting malicious properties into Object.prototype. The flaw occurs within the applyUpdate() and updateRecord() functions, which utilize Object.assign() to merge user-controlled data without filtering dangerous keys such as proto, constructor, or prototype.
Recommendations Update to version 1.69.3.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2026-42077
GHSA-2CJR-5V3H-V2W4

Affected Products

Evolver