Impact
A defect in carto-api-client’s addFilter function permits a remote attacker who controls the column argument to manipulate object prototype attributes. By supplying specially crafted values the library induces prototype pollution, which can alter the behavior of objects that inherit from Object.prototype and affect other parts of the client code.
Affected Systems
The affected component is CartoDB carto-api-client version 0.5.29. No additional vendors, products, or version ranges are identified in the CNA data.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk level. The EPSS score of less than 1% shows a low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, and the supplied data does not document a public exploit.
OpenCVE Enrichment