Product
The Mercado Pago Node.js SDK fails to sanitize user-supplied identifiers, allowing attackers to perform path traversal or query parameter injection to access unintended API endpoints within the merchant's token scope.