CVE-2026-16150

Source
https://cve.org/CVERecord?id=CVE-2026-16150
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-16150.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-16150
Published
2026-07-18T19:15:08.501Z
Modified
2026-07-22T05:29:53.601107475Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
RobinHerbots Inputmask Internal Deep Merge Helper extend.js extendAliases prototype pollution
Details

A vulnerability was found in RobinHerbots Inputmask up to 5.0.9. Affected by this issue is the function extendDefaults/extendDefinitions/extendAliases in the library lib/dependencyLibs/extend.js of the component Internal Deep Merge Helper. The manipulation results in improperly controlled modification of object prototype attributes. The attack may be performed from remote. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cna_assigner": "VulDB",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/16xxx/CVE-2026-16150.json",
    "cwe_ids": [
        "CWE-1321",
        "CWE-94"
    ]
}
References

Affected packages

Git / github.com/robinherbots/inputmask

Affected ranges

Type
GIT
Repo
https://github.com/robinherbots/inputmask
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "5.0.0"
        },
        {
            "last_affected": "5.0.0"
        },
        {
            "introduced": "5.0.1"
        },
        {
            "last_affected": "5.0.1"
        },
        {
            "introduced": "5.0.2"
        },
        {
            "last_affected": "5.0.2"
        },
        {
            "introduced": "5.0.3"
        },
        {
            "last_affected": "5.0.3"
        },
        {
            "introduced": "5.0.4"
        },
        {
            "last_affected": "5.0.4"
        },
        {
            "introduced": "5.0.5"
        },
        {
            "last_affected": "5.0.5"
        },
        {
            "introduced": "5.0.6"
        },
        {
            "last_affected": "5.0.6"
        },
        {
            "introduced": "5.0.7"
        },
        {
            "last_affected": "5.0.7"
        },
        {
            "introduced": "5.0.8"
        },
        {
            "last_affected": "5.0.8"
        },
        {
            "introduced": "5.0.9"
        },
        {
            "last_affected": "5.0.9"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

5.*
5.0.0
5.0.1
5.0.1-beta.0
5.0.1-beta.10
5.0.1-beta.12
5.0.1-beta.5
5.0.1-beta.7
5.0.2
5.0.2-beta.7
5.0.3
5.0.4
5.0.4-beta.1
5.0.4-beta.26
5.0.4-beta.33
5.0.4-beta.8
5.0.5
5.0.6
5.0.6-beta.11
5.0.6-beta.12
5.0.6-beta.14
5.0.6-beta.15
5.0.6-beta.18
5.0.6-beta.19
5.0.6-beta.20
5.0.6-beta.21
5.0.6-beta.22
5.0.6-beta.23
5.0.6-beta.24
5.0.6-beta.25
5.0.6-beta.29
5.0.6-beta.3
5.0.6-beta.31
5.0.6-beta.32
5.0.6-beta.37
5.0.6-beta.40
5.0.6-beta.42
5.0.6-beta.43
5.0.6-beta.5
5.0.6-beta.57
5.0.6-beta.6
5.0.6-beta.8
5.0.6-beta.9
5.0.7
5.0.7-beta.17
5.0.7-beta.18
5.0.7-beta.19
5.0.7-beta.23
5.0.7-beta.29
5.0.8
5.0.8-beta.0
5.0.8-beta.1
5.0.8-beta.15
5.0.8-beta.17
5.0.8-beta.25
5.0.8-beta.47
5.0.8-beta.7
5.0.8-beta.71
5.0.8-beta.72
5.0.9
5.0.9-beta.10
5.0.9-beta.16
5.0.9-beta.17
5.0.9-beta.18
5.0.9-beta.21
5.0.9-beta.24
5.0.9-beta.25
5.0.9-beta.28
5.0.9-beta.30
5.0.9-beta.32
5.0.9-beta.33
5.0.9-beta.35
5.0.9-beta.36
5.0.9-beta.37
5.0.9-beta.38
5.0.9-beta.39
5.0.9-beta.45
5.0.9-beta.51
5.0.9-beta.52
5.0.9-beta.53
5.0.9-beta.54
5.0.9-beta.56
5.0.9-beta.58
5.0.9-beta.59
5.0.9-beta.6
5.0.9-beta.60
5.0.9-beta.61
5.0.9-beta.62
5.0.9-beta.67
5.0.9-beta.68
5.0.9-beta.7
5.0.9-beta.70
5.0.9-beta.71
5.0.9-beta.72

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-16150.json"