A vulnerability labeled as critical has been found in mongo-object up to 3.0.2. Affected by this issue is the function
expandKey of the file util.js of the component util. Such manipulation leads to improperly controlled modification of object prototype attributes.
This vulnerability is referenced as CVE-2026-16266. It is possible to launch the attack remotely. No exploit is available.