Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-15699— spencermountain compromise Public Root API extend.js nlp.extend prototype pollution

CVSS 6.3 · Medium EPSS 0.26% · P17

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 2

VendorProductVersion RangeStatus
spencermountaincompromise14.15.0affected
14.15.1affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-15699

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
spencermountain compromise Public Root API extend.js nlp.extend prototype pollution
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability was identified in spencermountain compromise up to 14.15.1. Affected is the function nlp.extend of the file src/API/extend.js of the component Public Root API. The manipulation of the argument plugin leads to improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is b4644ab7179700df0607521f61c1ee9b5f78d89d. Applying a patch is the recommended action to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1321
Source: CVE Program / CVE List V5
Vulnerability Title
spencermountain compromise 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
spencermountain compromise是spencermountain公司开源的一款轻量级的 JavaScript 自然语言处理库,专注于将文本快速转换为可操作的结构化数据,支持词性标注、实体识别、文本变换等功能,体积仅约 250KB,可在浏览器和 Node.js 中运行。 spencermountain compromise 14.15.1及之前版本存在安全漏洞,该漏洞源于对文件src/API/extend.js中参数plugin的错误操作,导致对对象原型属性的修改控制不当,攻击者可能通过
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
spencermountaincompromise 14.15.0 cpe:2.3:a:spencermountain:compromise:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-15699

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-15699

登录查看更多情报信息。

Patches & Fixes for CVE-2026-15699 (1)

Proof of Concept for CVE-2026-15699 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-15699

No comments yet


Leave a comment