High severity8.2GHSA Advisory· Published Jul 16, 2026· Updated Jul 17, 2026
CVE-2026-45325
CVE-2026-45325
Description
Gestor de Oferta is a web application for managing mobility service offerings. Prior to 20260509.0340.15, @tmlmobilidade/utils has a prototype pollution vulnerability in setValueAtPath() in packages/utils/src/generic/value-at-path.ts because unsafe path segments are not blocked. This issue is fixed in version 20260509.0340.15.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@tmlmobilidade/utilsnpm | < 20260509.0340.15 | 20260509.0340.15 |
Affected products
1- Range: < 20260509.0340.15
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.