A vulnerability was found in thomaspoignant scim-patch up to 0.9.0. It has been declared as critical. This affects the function scimPatch. The manipulation of the argument Value results in improperly controlled modification of object prototype attributes.

This vulnerability is known as CVE-2026-48170. It is possible to launch the attack remotely. No exploit is available.

It is recommended to upgrade the affected component.