PatchSiren

mercadopago CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH mercadopago CVE published 2026-08-24

CVE-2026-76842

The Mercado Pago Node.js SDK is vulnerable to path injection attacks due to improper encoding of user-supplied identifiers in API request paths. This allows an attacker to manipulate the request path and potentially access sensitive resources within the merchant's token scope. The vulnerability arises from the SDK's interpolation of caller-supplied identifiers into API request paths without percent-encodi [truncated]