Prototype pollution in Compass - CVE-2026-9101
Published: August 18, 2026 / Updated: August 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute commands.
The vulnerability exists due to prototype pollution in csv parsing logic during import when parsing a crafted CSV file. A remote attacker can trick a victim into importing a crafted CSV file to execute commands.
User interaction is required, and exploitation depends on specific user behavior that leads to a one-click action through shell.openExternal with an untrusted file path.