Sploitus

CVE-2026-15598

1 known exploit for CVE-2026-15598

A weakness has been identified in antv layout 2.0.0. This impacts the function setNestedValue in the library lib/util/object.js. Executing a manipulation of the argument path can lead to improperly controlled modification of object prototype attributes. The attack can be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.

Affected products
Xlayout
CVSS 2.0
6.5 MEDIUM
CVSS 3.1
6.3 MEDIUM
EPSS
0.3% (24th percentile)
Weakness
CWE-94, CWE-1321
NVD status
Deferred
Published
2026-07-13
CVE-2026-15598 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2026-15598

Proof-of-concept code and exploit modules indexed by Sploitus