Executive brief
A vulnerability was found in the 'compromise' library, a popular tool used for natural language processing in JavaScript applications. An attacker could exploit this flaw to modify the behavior of the application by injecting malicious properties into shared system objects. This could lead to application crashes, data corruption, or unauthorized changes to how the software processes information.
Technical details
A prototype pollution vulnerability exists in spencermountain compromise up to version 14.15.1. The flaw is located in the `nlp.extend` function within `src/API/extend.js`. When a plugin object containing a `model` property is passed to the API, the library performs a recursive merge without properly sanitizing keys. An attacker can provide a crafted plugin containing special keys like `__proto__`, `constructor`, or `prototype` to inject properties into `Object.prototype`. This can be exploited remotely if the application processes user-controlled plugin configurations. A patch has been released in commit b4644ab7179700df0607521f61c1ee9b5f78d89d.
Affected products
- spencermountain compromise up to 14.15.1
Timeline
- 2026-06-11: disclosed: Issue reported on GitHub repository
- 2026-07-14: advisory: NVD and VulDB publication date
- 2026-07-14: patched: Vendor released fix via commit b4644ab
References
- https://github.com/spencermountain/compromise/
- https://github.com/spencermountain/compromise/commit/b4644ab7179700df0607521f61c1ee9b5f78d89d
- https://github.com/spencermountain/compromise/issues/1208
- https://vuldb.com/cve/CVE-2026-15699
- https://vuldb.com/submit/856016
- https://vuldb.com/vuln/378246
- https://vuldb.com/vuln/378246/cti