CVE-2026-28794 | middleapi orpc up to 1.13.5 prototype pollution (GHSA-m272-9rp6-32mc)
A vulnerability labeled as critical has been found in middleapi orpc up to 1.13.5. Affected is an unknown function. Executing a manipulation can lead to improperly controlled modification of object prototype attributes.
This vulnerability is tracked as CVE-2026-28794. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.