Bug 2498547 (CVE-2026-15187)

Summary: CVE-2026-15187 enquirer: Enquirer: Prototype pollution vulnerability allows remote attackers to modify object attributes
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aadhikar, aazores, aruklets, ataylor, bsmejkal, cmah, dbruscin, dkeler, doconnor, dschmidt, dymurray, eaguilar, ebaron, ehugonne, gparvin, ibolton, jachapma, jlanda, jmatsuok, jmatthew, jmontleo, jolong, jtolenti, kaycoth, kshier, kvanderr, lchilton, manissin, mreynolds, pgaikwad, pjindal, progier, rhaigner, rhel-process-autobot, rjohnson, sfeifer, simaishi, slucidi, snegrini, spichugi, sseago, stcannon, suppawar, tbordaz, teagle, thason, vashirov, watson-tool-maintainers, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in enquirer, a command-line prompt tool. A remote attacker could exploit a vulnerability in the `Enquirer.set` function by manipulating the `question.name` argument. This improper handling of object prototype attributes can lead to prototype pollution, allowing an attacker to modify the behavior of an application. This could result in unexpected application behavior or potentially lead to further attacks.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-07-09 16:01:53 UTC
A security flaw has been discovered in enquirer up to 2.4.1. Affected is the function Enquirer.set of the component Public Package API. The manipulation of the argument question.name results in improperly controlled modification of object prototype attributes. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report.