Impact
Gestor de Oferta is a web application for managing mobility service offerings. Prior to 20260509.0340.15, the @tmlmobilidade/utils library contains a prototype pollution flaw in its setValueAtPath() function because unsafe path segments are not blocked, allowing an attacker to inject properties into the Object prototype chain. This can change the application’s behavior and could lead to unauthorized actions if the polluted properties influence code execution. The flaw was fixed in version 20260509.0340.15.
Affected Systems
The tmlmobilidade:go product, specifically the Gestor de Oferta web application, is vulnerable. All releases before 20260509.0340.15 contain the flaw, which was fixed in the 20260509.0340.15 version.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.2, indicating high severity. The EPSS score of < 1% suggests a low probability of exploitation, and it is not listed in the CISA KEV catalog. Exploitation likely requires an attacker to supply crafted input that traverses setValueAtPath, such as through a form or API that accepts structured data with path segments. The attack could be performed by clients or malicious users interacting with the application.
OpenCVE Enrichment
Github GHSA