Medium [CVE-2026-15187] Prototype pollution vulnerability allows remote attackers to modify object attributes
This medium-severity Red Hat Linux advisory covers CVE-2026-15187 affecting Red Hat Hardened Images, Cryostat 4, Migration Toolkit for Containers.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
A security flaw has been discovered in enquirer up to 2.4.1. Affected is the function Enquirer.set of the component Public Package API.
The manipulation of the argument question.name results in improperly controlled modification of object prototype attributes. The attack can be launched remotely.
The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report.
A flaw was found in enquirer, a command-line prompt tool. A remote attacker could exploit a vulnerability in the `Enquirer.set` function by manipulating the `question.name` argument.
This improper handling of object prototype attributes can lead to prototype pollution, allowing an attacker to modify the behavior of an application. This could result in unexpected application behavior or potentially lead to further attacks.
This could lead to unexpected application behavior in Red Hat products that use `enquirer` to process untrusted input, as an attacker could modify object attributes. The public availability of an exploit increases the risk.
Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N). Weakness: CWE-915.
Affected products named by the advisory: Red Hat Hardened Images; Cryostat 4; Migration Toolkit for Containers; Multicluster Engine for Kubernetes; and 17 more.
- 2.4.1
Official advisory · high-confidence parse· fetched 11 days ago·verify at source
- rust-main-1.96.1-1.hum1
- RHSA-2026:34975
Official advisory · high-confidence parse· fetched 11 days ago·verify at source
Mitigation checklist
- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Official advisory · high-confidence parse· fetched 11 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.