PT-2026-36855 · Evolve · Evolver
Xeloxa
·
Published
2026-04-22
·
Updated
2026-05-04
·
CVE-2026-42077
CVSS v3.1
5.2
Medium
| Vector | AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Evolver versions prior to 1.69.3
Description
A prototype pollution issue in the mailbox store module allows attackers to modify the behavior of all JavaScript objects by injecting malicious properties into Object.prototype. The flaw occurs within the
applyUpdate() and updateRecord() functions, which utilize Object.assign() to merge user-controlled data without filtering dangerous keys such as proto, constructor, or prototype.Recommendations
Update to version 1.69.3.
Exploit
Fix
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Evolver