CVE-2026-16008
Last modified
CVE-2026-16008 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. A security vulnerability has been detected in sagold json-schema-library 11.5.0/11.5.1. This impacts the function parsePropertyDependencies of the file src/keywords/propertyDependencies.ts.
Description
A security vulnerability has been detected in sagold json-schema-library 11.5.0/11.5.1. This impacts the function parsePropertyDependencies of the file src/keywords/propertyDependencies.ts. The manipulation leads to improperly controlled modification of object prototype attributes. The attack can be initiated remotely. Upgrading to version 11.6.0 will fix this issue. The identifier of the patch is 432287ee6f68a02ce6f015354618486ec427a32d. It is advisable to upgrade the affected component.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| sagold | json-schema-library | 11.5.0; 11.5.1 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-16008?
How severe is CVE-2026-16008?
How do I fix CVE-2026-16008?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-16002The affected product is vulnerable to an Out-of-bounds read,…8.8
- CVE-2026-16003Exposed IOCTL with Insufficient Access Control in Armoury Cr…2
- CVE-2026-16004Exposed IOCTL with Insufficient Access Control in Armoury Cr…5.9
- CVE-2026-16005Release of Invalid Pointer or Reference in Armoury Crate dri…5.8
- CVE-2026-16006Exposure of Sensitive System Information to an Unauthorized …5.7
- CVE-2026-16007AppFlowy's qcuiknote feature is affected by a SQL injection …7.1
- CVE-2026-16009A vulnerability was detected in itsourcecode Hospital Manage…6.3
- CVE-2026-1601A weakness has been identified in Totolink A7000R 4.1cu.4154…6.3
- CVE-2026-16013A vulnerability has been found in liftoff-sr CIPster up to 6…5.5
- CVE-2026-16014A vulnerability was found in code-projects Hospital Bed Mana…7.3
- CVE-2026-16015A vulnerability was determined in poco-ai poco-claw up to 0.…6.3
- CVE-2026-16016A vulnerability was identified in poco-ai poco-claw up to 0.…7.3
Are you affected by CVE-2026-16008?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
