VYPR

sdk-nodejs

by Mercado Pago

CVEs (1)

  • CVE-2026-76842HigAug 24, 2026
    risk 0.46cvss 8.2epss

    The Mercado Pago Node.js SDK interpolates caller-supplied identifiers into API request paths without percent-encoding them, so characters that are structural in a URL survive into the outgoing request. The payment (get, capture, cancel), paymentRefund (create, total, list, get),…