A security vulnerability has been detected in RubyLouvre avalon up to 2.2.10. The impacted element is an unknown function of the file src/filters/index.js of the component Template Filter Handler. Such manipulation leads to improperly controlled modification of object prototype attributes. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Mon, 15 Jun 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in RubyLouvre avalon up to 2.2.10. The impacted element is an unknown function of the file src/filters/index.js of the component Template Filter Handler. Such manipulation leads to improperly controlled modification of object prototype attributes. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | RubyLouvre avalon Template Filter index.js prototype pollution | |
| First Time appeared |
Rubylouvre
Rubylouvre avalon |
|
| Weaknesses | CWE-1321 CWE-94 |
|
| CPEs | cpe:2.3:a:rubylouvre:avalon:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Rubylouvre
Rubylouvre avalon |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-15T02:15:07.361Z
Reserved: 2026-06-14T12:27:55.933Z
Link: CVE-2026-12209
No data.
Status : Received
Published: 2026-06-15T03:16:24.167
Modified: 2026-06-15T03:16:24.167
Link: CVE-2026-12209
No data.
OpenCVE Enrichment
Updated: 2026-06-15T04:30:29Z