Junglewise Threat Intelligence

CVE-2026-76842: Mercado Pago Node.js SDK path traversal in API clients

CVE-2026-76842 · Severity: high · CVSS 8.2 · Published 2026-08-24

Executive brief

The Mercado Pago Node.js SDK fails to properly encode user-supplied identifiers when constructing API request paths, allowing an attacker to manipulate URLs and access unintended resources. If an application passes untrusted data (such as a payment or customer ID) to affected SDK methods without validation, an attacker can inject path traversal sequences or query parameters to reach other endpoints and potentially steal or modify merchant data using the application's access token.

Technical details

The vulnerability is a path traversal / URL manipulation flaw in multiple SDK clients (payment, paymentRefund, advancedPayment, disbursementRefund). The clients build API request paths as template literals without percent-encoding identifiers, e.g., `RestClient.fetch(/v1/payments/${id}, ...)`. An attacker can inject sequences like `../`, `./`, or `?` that are normalized or interpreted by the WHATWG URL parser, redirecting requests to different endpoints while preserving the merchant's authentication token in the Authorization header. The vulnerability affects get/capture/cancel methods on payment and advancedPayment clients, and create/list/get methods on paymentRefund and disbursementRefund clients. The SDK already implements the required mitigation (encodePathParam helper) in src/utils/path.ts, but it was not applied consistently. An attack requires the application to pass untrusted identifiers to these methods without prior ownership validation. A patch should apply the existing encodePathParam helper to all affected client methods.

Affected products

  • Mercado Pago Node.js SDK <unknown

Timeline

  • 2026-08-24: disclosed: CVE-2026-76842 published

References