Junglewise Threat Intelligence

CVE-2026-16266: longshotlabs mongo-object Prototype Pollution in expandKey

CVE-2026-16266 · Severity: medium · CVSS 4 · Published 2026-07-21

Executive brief

The mongo-object library, used for interacting with MongoDB documents and modifiers, is vulnerable to a security flaw that allows attackers to manipulate the internal structure of JavaScript objects. By providing specially crafted input, an attacker can inject unauthorized properties into the application's memory. This can lead to unexpected application behavior, bypass of security checks, or service instability.

Technical details

A Prototype Pollution vulnerability exists in the `expandKey()` function within `util.js` (or `util.ts`) of the mongo-object library. The root cause is improper validation of property paths, allowing special keys such as `__proto__`, `constructor`, or `prototype` to be processed. A remote attacker can exploit this by supplying a crafted property path to the function, enabling them to inject or modify properties on the global `Object.prototype`. This can result in property injection, denial of service, or potentially remote code execution depending on how the application utilizes the polluted objects. The issue is fixed in version 3.0.3 by adding protection against these sensitive keys.

Affected products

  • longshotlabs mongo-object < 3.0.3

Timeline

  • 2025-11-02: disclosed: Issue reported on GitHub
  • 2026-07-20: advisory: Snyk advisory published
  • 2026-07-21: patched: CVE published and fix confirmed in version 3.0.3

References