CVE-2026-73562 | Automattic Mongoose up to 6.13.9/7.8.9/8.24.0/9.7.1 Update Casting body prototype pollution
A vulnerability classified as critical has been found in Automattic Mongoose up to 6.13.9/7.8.9/8.24.0/9.7.1. Affected by this issue is the function Schema.prototype.path/Schema.prototype._getPathType of the component Update Casting. This manipulation of the argument body causes improperly controlled modification of object prototype attributes.
This vulnerability is handled as CVE-2026-73562. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More