Security Flaw in oRPC API Tool by MiddleAPI
CVE-2026-103036

6.5MEDIUM

Key Information:

Vendor

Middleapi

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-103036?

Prior to version 1.14.9, oRPC's @orpc/json-schema SmartCoercionPlugin could be exploited through object input schemas. Attackers were able to supply the proto property or Object.prototype member names, allowing them to manipulate inherited properties of the coerced request object. This could lead to unintended effects on other operations like handler evaluations or configuration lookups while bypassing certain security validations. The flaw has been addressed in version 1.14.9, which eliminates the potential for such prototype pollution attacks.

Affected Version(s)

orpc < 1.14.9

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.