CartoDB carto-api-client filters.ts addFilter prototype pollution
Published Jul 18, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.45%
Description
A vulnerability has been found in CartoDB carto-api-client 0.5.29. This impacts the function addFilter of the file src/filters.ts. Such manipulation of the argument column leads to improperly controlled modification of object prototype attributes. The attack can be executed remotely. The project was informed of the problem early through an issue report but has not responded yet.
Affected products
-
Affected
- 0.5.29
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| CartoDB | Carto-Api-Client | unknown | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45397 Advisory
- https://github.com/CartoDB/carto-api-client/ product
- https://github.com/CartoDB/carto-api-client/issues/299 exploitissue-tracking
- https://vuldb.com/cve/CVE-2026-16151 third-party-advisory
- https://vuldb.com/submit/857043 third-party-advisory
- https://vuldb.com/vuln/379917 vdb-entrytechnical-description
- https://vuldb.com/vuln/379917/cti signaturepermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45397 | Advisory | |
| https://github.com/CartoDB/carto-api-client/ | product | |
| https://github.com/CartoDB/carto-api-client/issues/299 | exploitissue-tracking | |
| https://vuldb.com/cve/CVE-2026-16151 | third-party-advisory | |
| https://vuldb.com/submit/857043 | third-party-advisory | |
| https://vuldb.com/vuln/379917 | vdb-entrytechnical-description | |
| https://vuldb.com/vuln/379917/cti | signaturepermissions-required |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data