HIGH
mercadopago
CVE published 2026-08-24
CVE-2026-76842
The Mercado Pago Node.js SDK is vulnerable to path injection attacks due to improper encoding of user-supplied identifiers in API request paths. This allows an attacker to manipulate the request path and potentially access sensitive resources within the merchant's token scope. The vulnerability arises from the SDK's interpolation of caller-supplied identifiers into API request paths without percent-encodi [truncated]