CWE-1321— Improperly Controlled Modification of Object Prototype Attributes (Prototype Pollution)
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.— MITRE CWE catalog
622 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1321page 1 of 13
- CVE-2026-34621CRITICALCVSS 8.6EG 9.6⚠ KEV2026-04-11
Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the …
- CVE-2026-105857CRITICALCVSS 10.0EG 10.02026-10-06
Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can craft a form submission that executes code remotely…
- CVE-2026-44005CRITICALCVSS 10.0EG 10.02026-05-13
vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes into the underlying host objects with otherReflectSet() and …
- CVE-2026-25881CRITICALCVSS 10.0EG 10.02026-02-09
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.31, a sandbox escape vulnerability allows sandboxed code to mutate host built-in prototypes by laundering the isGlobal protection flag through array literal intermediaries. When a …
- CVE-2026-25150CRITICALCVSS 10.0EG 10.02026-02-03
Qwik is a performance focused javascript framework. Prior to version 1.19.0, a prototype pollution vulnerability exists in the formToObj() function within @builder.io/qwik-city middleware. The function processes form field names with dot n…
- CVE-2026-25142CRITICALCVSS 10.0EG 10.02026-02-02
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.27, SanboxJS does not properly restrict __lookupGetter__ which can be used to obtain prototypes, which can be used for escaping the sandbox / remote code execution. This vulnerabil…
- CVE-2024-39008CRITICALCVSS 10.0EG 10.02024-07-01
robinweser fast-loops v1.1.3 was discovered to contain a prototype pollution via the function objectMergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary propert…
- CVE-2024-38999CRITICALCVSS 10.0EG 10.02024-07-01
jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary prop…
- CVE-2022-29823CRITICALCVSS 10.0EG 10.02022-10-26
Feather-Sequalize cleanQuery method uses insecure recursive logic to filter unsupported keys from the query object. This results in a Remote Code Execution (RCE) with privileges of application.
- CVE-2022-24760CRITICALCVSS 10.0EG 10.02022-03-12
Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in Parse Server. This vulnerability affects Parse Server in the default configuration with MongoDB. Th…
- CVE-2020-12079CRITICALCVSS 10.0EG 10.02020-04-23
Beaker before 0.8.9 allows a sandbox escape, enabling system access and code execution. This occurs because Electron context isolation is not used, and therefore an attacker can conduct a prototype-pollution attack against the Electron int…
- CVE-2023-26122CRITICALCVSS 8.8EG 10.02023-04-11
All versions of the package safe-eval are vulnerable to Sandbox Bypass due to improper input sanitization. The vulnerability is derived from prototype pollution exploitation. Exploiting this vulnerability might result in remote code execut…
- CVE-2023-26121CRITICALCVSS 7.5EG 10.02023-04-11
All versions of the package safe-eval are vulnerable to Prototype Pollution via the safeEval function, due to improper sanitization of its parameter content.
- CVE-2026-44791CRITICALCVSS 9.9EG 9.92026-06-23
n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could bypass the patch for CVE-2026-42232 in the XML node. When combined with ot…
- CVE-2026-44789CRITICALCVSS 9.9EG 9.92026-06-23
n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via an unvalidated pagination parameter…
- CVE-2026-49252CRITICALCVSS 9.9EG 9.92026-06-18
deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. Versions prior to 10.0.5 are vulnerable to Prototype Pollution. Exploitation can lead to potential privilege escalation fr…
- CVE-2026-32621CRITICALCVSS 9.9EG 9.92026-03-16
Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Prior to 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2, a vulnerability exists in query plan execution within the gateway that may allow pollution of O…
- CVE-2025-25015CRITICALCVSS 9.9EG 9.92025-03-05
Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP requests. In Kibana versions >= 8.15.0 and < 8.17.1, this is exploitable by users with the Viewer role. In Kibana versi…
- CVE-2026-57926CRITICALCVSS 9.8EG 9.82026-06-26
In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
- CVE-2026-44966CRITICALCVSS 9.8EG 9.82026-05-26
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pollution vulnerability was discovered in velocityjs. This issue occurs during the processing of #set directives in Veloci…
- CVE-2025-63704CRITICALCVSS 9.8EG 9.82026-05-07
NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly created object.
- CVE-2025-63703CRITICALCVSS 9.8EG 9.82026-05-07
npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js().
- CVE-2026-40190CRITICALCVSS 9.8EG 9.82026-04-10
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScript/TypeScript SDK (langsmith) contains an incomplete prototype pollution fix in its internally vendored lodash set() ut…
- CVE-2026-33994CRITICALCVSS 9.8EG 9.82026-03-27
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Starting in version 2.0.39 and prior to version 3.0.25, a prototype pollution vulnerability exists in the `parse_str` function of the npm package…
- CVE-2026-33993CRITICALCVSS 9.8EG 9.82026-03-27
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.25, the `unserialize()` function in `locutus/php/var/unserialize` assigns deserialized keys to plain objects via bracket not…
- CVE-2026-33228CRITICALCVSS 9.8EG 9.82026-03-20
flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the inter…
- CVE-2026-29063CRITICALCVSS 9.8EG 9.82026-03-06
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. Th…
- CVE-2026-28794CRITICALCVSS 9.8EG 9.82026-03-06
oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1.13.6, a prototype pollution vulnerability exists in the RPC JSON deserializer of the @orpc/client package. The vulnerab…
- CVE-2026-27837CRITICALCVSS 9.8EG 9.82026-02-26
Dottie provides nested object access and manipulation in JavaScript. Versions 2.0.4 through 2.0.6 contain an incomplete fix for CVE-2023-26132. The prototype pollution guard introduced in commit `7d3aee1` only validates the first segment o…
- CVE-2026-2964CRITICALCVSS 9.8EG 9.82026-02-23
A vulnerability was identified in higuma web-audio-recorder-js 0.1/0.1.1. Impacted is the function extend in the library lib/WebAudioRecorder.js of the component Dynamic Config Handling. Such manipulation leads to improperly controlled mod…
- CVE-2026-26021CRITICALCVSS 9.8EG 9.82026-02-11
set-in provides the set value of nested associative structure given array of keys. A prototype pollution vulnerability exists in the the npm package set-in (>=2.0.1, < 2.0.5). Despite a previous fix that attempted to mitigate prototype pol…
- CVE-2026-24888CRITICALCVSS 9.8EG 9.82026-01-28
Maker.js is a 2D vector line drawing and shape modeling for CNC and laser cutters. In versions up to and including 0.19.1, the `makerjs.extendObject` function copies properties from source objects without proper validation, potentially exp…
- CVE-2025-61140CRITICALCVSS 9.8EG 9.82026-01-28
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
- CVE-2026-23736CRITICALCVSS 9.8EG 9.82026-01-21
seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, due to improper input validation, a malicious object key can lead to prototype pollution during JSO…
- CVE-2026-21854CRITICALCVSS 9.8EG 9.82026-01-07
The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to 02 January 2025, an authentication bypass vulnerability in the login endpoint allows any unauthenticated user to gain full admin access to the Tarkov Data Manager a…
- CVE-2025-66456CRITICALCVSS 9.8EG 9.82025-12-09
Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Versions 1.4.0 through 1.4.16 contain a prototype pollution vulnerability in `mergeDeep` after merging results …
- CVE-2025-57321CRITICALCVSS 9.8EG 9.82025-09-24
A Prototype Pollution vulnerability in the util-deps.addFileDepend function of magix-combine-ex versions thru 1.2.10 allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS)…
- CVE-2025-57347CRITICALCVSS 9.8EG 9.82025-09-24
A vulnerability exists in the 'dagre-d3-es' Node.js package version 7.0.9, specifically within the 'bk' module's addConflict function, which fails to properly sanitize user-supplied input during property assignment operations. This flaw al…
- CVE-2011-10019CRITICALCVSS 9.8EG 9.82025-08-13
Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to properly sanitize input passed via the search[send][] parameter, which is dynamically invoked us…
- CVE-2025-49223CRITICALCVSS 9.8EG 9.82025-06-04
billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
- CVE-2024-38988CRITICALCVSS 9.8EG 9.82025-03-28
alizeait unflatto <= 1.0.2 was discovered to contain a prototype pollution via the method exports.unflatto at /dist/index.js. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting ar…
- CVE-2024-38985CRITICALCVSS 9.8EG 9.82025-03-28
janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() method at setIn (lib/index.js:90). This vulnerability allows attackers to execute arbitrary code or cause a Denial of Serv…
- CVE-2024-24292CRITICALCVSS 9.8EG 9.82025-03-28
A Prototype Pollution issue in Aliconnect /sdk v.0.0.6 allows an attacker to execute arbitrary code via the aim function in the aim.js component.
- CVE-2025-25977CRITICALCVSS 9.8EG 9.82025-03-10
An issue in canvg v.4.0.2 allows an attacker to execute arbitrary code via the Constructor of the class StyleElement.
- CVE-2024-56059CRITICALCVSS 9.8EG 9.82024-12-18
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in farinspace Partners partners allows Object Injection.This issue affects Partners: from n/a through <= 0.2.0.
- CVE-2024-52441CRITICALCVSS 9.8EG 9.82024-11-20
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Rajesh Thanoch Quick Learn quick-learn allows Object Injection.This issue affects Quick Learn: from n/a through <= 1.0.1.
- CVE-2024-45435CRITICALCVSS 9.8EG 9.82024-08-29
Chartist 1.x through 1.3.0 allows Prototype Pollution via the extend function.
- CVE-2024-38989CRITICALCVSS 9.8EG 9.82024-08-12
izatop bunt v0.29.19 was discovered to contain a prototype pollution via the component /esm/qs.js. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
- CVE-2024-38983CRITICALCVSS 9.8EG 9.82024-07-30
Prototype Pollution in alykoshin mini-deep-assign v0.0.8 allows an attacker to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via the _assign() method at (/lib/index.js:91)
- CVE-2024-39012CRITICALCVSS 9.8EG 9.82024-07-30
ais-ltd strategyen v0.4.0 was discovered to contain a prototype pollution via the function mergeObjects. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
Map vulnerabilities like CWE-1321 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1321 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →