PT-2026-41773 · Npm · @Tmlmobilidade/Utils

Published

2026-05-18

·

Updated

2026-05-18

·

CVE-2026-45325

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

Impact

Prototype pollution vulnerability in @tmlmobilidade/utils for setValueAtPath().

Patches

A fix is available in versions 20260509.0340.15 and up.

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2026-45325
GHSA-CMXG-94MG-JQ94

Affected Products

@Tmlmobilidade/Utils