Executive brief
A security vulnerability exists in a utility library used by the Gestor de Oferta mobility service platform. An attacker could exploit this flaw to modify the internal behavior of the application, potentially leading to unauthorized data modification or service disruptions. This issue affects how the application handles data paths and has been addressed in the latest software update.
Technical details
A prototype pollution vulnerability (CWE-1321) exists in the @tmlmobilidade/utils package within the setValueAtPath() function located in packages/utils/src/generic/value-at-path.ts. The root cause is a failure to block or sanitize unsafe path segments such as '__proto__', 'constructor', or 'prototype' when splitting the input path string. A remote, unauthenticated attacker can exploit this by providing a specially crafted path, allowing them to inject properties into the global Object prototype. This can result in application-wide integrity issues or a partial denial of service. The vulnerability is fixed in version 20260509.0340.15 by implementing a blocklist for these unsafe keys.
Affected products
- tmlmobilidade @tmlmobilidade/utils < 20260509.0340.15
Timeline
- 2026-05-09: patched: Fix version 20260509.0340.15 released.
- 2026-05-13: advisory: GitHub Security Advisory GHSA-cmxg-94mg-jq94 published.
- 2026-07-16: disclosed: CVE-2026-45325 published to NVD.