Executive brief
A security vulnerability exists in the APIDevTools json-schema-ref-parser library, which is used to process and resolve JSON Schema references. An attacker can exploit this flaw to modify the internal behavior of the application, potentially leading to service crashes or unauthorized changes to how data is processed. This issue is particularly relevant for applications that allow users to provide their own JSON Schema pointers or paths.
Technical details
A prototype pollution vulnerability exists in APIDevTools json-schema-ref-parser up to version 15.3.5 within the `lib/pointer.ts` component. The `Refs.set()` and `Pointer.set()` functions fail to properly sanitize JSON Pointer tokens, allowing the use of dangerous keys such as `__proto__`, `constructor`, and `prototype`. A remote attacker with the ability to provide a crafted JSON Pointer string can trigger a nested write that modifies the `Object.prototype`. This can result in application-wide logic corruption, denial of service, or further exploitation depending on how the library is integrated. The issue is resolved in version 15.3.6 by blocking unsafe pointer set tokens.
Affected products
- APIDevTools json-schema-ref-parser up to 15.3.5
Timeline
- 2026-06-08: disclosed: Issue reported on GitHub repository
- 2026-06-11: patched: Version 15.3.6 released with fix
- 2026-07-09: advisory: CVE-2026-15195 published
References
- https://github.com/APIDevTools/json-schema-ref-parser/
- https://github.com/APIDevTools/json-schema-ref-parser/commit/a786bc6afc3674f650496472ee93d5cf74c4bd84
- https://github.com/APIDevTools/json-schema-ref-parser/issues/421
- https://github.com/APIDevTools/json-schema-ref-parser/releases/tag/v15.3.6
- https://vuldb.com/cve/CVE-2026-15195
- https://vuldb.com/submit/851809
- https://vuldb.com/vuln/377123