CVE-2026-76842 | Mercado Pago SDK up to 3.4.0 API Request Path index.ts RestClient.fetch ID redirect (ID 451)
A vulnerability has been found in Mercado Pago SDK up to 3.4.0 and classified as problematic. Impacted is the function RestClient.fetch of the file src/clients/payment/get/index.ts of the component API Request Path. This manipulation of the argument ID causes open redirect.
This vulnerability appears as CVE-2026-76842. The attack may be initiated remotely. There is no available exploit.
It is recommended to apply a patch to fix this issue.VulDB Recent EntriesRead More