Mercator, Path Traversal, CVE-2026-17495 (Medium) -DC-Oct2026-2720

Listen to this Post

Mercator is an open-source web application for mapping information systems. A path traversal vulnerability exists in the moment JavaScript library, which is used by Mercator for date handling. In moment versions 2.29.2 through 2.30.1, a specially crafted non-string object passed to `moment.locale()` can bypass the locale-name path-traversal guard. The guard assumes the input is a string, so an object whose `match()` method satisfies the check while its `toString()` returns a traversal path reaches an internal `require()` call with attacker-controlled path segments. This is an incomplete fix for CVE-2022-24785 and primarily affects npm (server-side) users that pass user-provided input directly to moment.locale(). The issue is fixed in moment 2.31.0, and users should upgrade to 2.31.0 or later. As a workaround, validate that any user-supplied input is a string before passing it to moment.locale(). The vulnerability is classified as CWE-27: Path Traversal. The CVSS 3.x base score is 5.9, rated as Medium. Mercator release 2026.10.03 includes a bump of moment from 2.30.1 to 2.31.0, which addresses this issue.

DailyCVE Form:

Platform: Mercator
Version: 2.30.1
Vulnerability: Path Traversal
Severity: Medium
date: 2026-09-15

Prediction: 2026-10-03

What Undercode Say:

Analytics:

List Mercator dependencies
composer show
Check installed moment version
npm list moment

How Exploit: (Educational Purposes!)

const moment = require('moment');
moment.locale({
match: () => true,
toString: () => '../../../../etc/passwd'
});

Protection:

Update moment to 2.31.0.

Impact:

Path traversal, potential file read.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top