CWE-1321— Improperly Controlled Modification of Object Prototype Attributes (Prototype Pollution)
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.— MITRE CWE catalog
622 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1321page 10 of 13
- CVE-2026-101902MEDIUMCVSS 6.9EG 6.92026-09-28
Axios is a promise-based HTTP client for the browser and Node.js. From 0.27.2 until 0.34.0 and 1.20.0, Axios default-instance requests that omit an explicit method can read an inherited method value from Object.prototype. If another vulner…
- CVE-2026-101900MEDIUMCVSS 6.9EG 6.92026-09-28
Axios is a promise-based HTTP client for the browser and Node.js. From 1.12.0 until 1.20.0, ResolveConfig reads inherited Symbol.toStringTag, append, and getHeaders properties while resolving FormData headers. A separate same-process proto…
- CVE-2026-85063MEDIUMCVSS 6.9EG 6.92026-09-03
node-csv is a full-featured CSV parser with a simple API that is tested against large datasets. Prior to 7.0.2, csv-parse with the columns and group_columns_by_name options enabled treats a duplicate __proto__ header as an existing propert…
- CVE-2026-41238MEDIUMCVSS 6.9EG 6.92026-04-23
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable to a prototype pollution-based XSS bypass. When an application uses `DOMPurify.sanitize()` with the default confi…
- CVE-2025-32014MEDIUMCVSS 6.9EG 6.92025-04-07
estree-util-value-to-estree converts a JavaScript value to an ESTree expression. When generating an ESTree from a value with a property named __proto__, valueToEstree would generate an object that specifies a prototype instead. This vulner…
- CVE-2024-52810MEDIUMCVSS 6.9EG 6.92024-11-29
@intlify/shared is a shared library for the intlify project. The latest version of @intlify/shared (10.0.4) is vulnerable to Prototype Pollution through the entry function(s) lib.deepCopy. An attacker can supply a payload with Object.proto…
- CVE-2025-48054MEDIUMCVSS 6.8EG 6.82025-05-27
Radashi is a TypeScript utility toolkit. Prior to version 12.5.1, the set function within the Radashi library is vulnerable to prototype pollution. If an attacker can control parts of the path argument to the set function, they could poten…
- CVE-2024-34148MEDIUMCVSS 6.8EG 6.82024-05-02
Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically disables the fix for CVE-2016-3721 whenever a build is triggered from a release tag, by setting the Java system property 'hudson.model.ParametersAction.ke…
- CVE-2021-39205MEDIUMCVSS 6.8EG 6.82021-09-15
Jitsi Meet is an open source video conferencing application. Versions prior to 2.0.6173 are vulnerable to client-side cross-site scripting via injecting properties into JSON objects that were not properly escaped. There are no known incide…
- CVE-2021-21368MEDIUMCVSS 6.7EG 6.72021-03-12
msgpack5 is a msgpack v5 implementation for node.js and the browser. In msgpack5 before versions 3.6.1, 4.5.1, and 5.2.1 there is a "Prototype Poisoning" vulnerability. When msgpack5 decodes a map containing a key "__proto__", it assigns t…
- CVE-2026-107301MEDIUMCVSS 6.5EG 6.52026-10-08
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, constructing msgpack5 with an empty or partial options object disables the default protoAction: 'error' protection. A decoded map containing a __proto__ k…
- CVE-2026-107353MEDIUMCVSS 6.5EG 6.52026-10-07
traverse (npm) versions 0.3.6 through 0.3.9, 0.4.0 through 0.4.6, 0.5.0 through 0.5.2, and 0.6.0 through 0.6.11 allow prototype pollution through set(). When the path passed to set() crosses a primitive value, the next path segment is reso…
- CVE-2026-103918MEDIUMCVSS 6.5EG 6.52026-10-02
oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.10, the @orpc/zod ZodSmartCoercionPlugin and experimental_ZodSmartCoercionPlugin collect object and record properties in plai…
- CVE-2026-103036MEDIUMCVSS 6.5EG 6.52026-10-02
oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.9, the @orpc/json-schema SmartCoercionPlugin uses JsonSchemaCoercer to collect object properties in a plain object and to res…
- CVE-2026-86078MEDIUMCVSS 6.5EG 6.52026-09-08
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI workflow summary used node names and connection keys from stored workflows as ordinary object keys. A workflow submitted through the REST API c…
- CVE-2026-73562MEDIUMCVSS 6.5EG 6.52026-08-13
Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.24.1, and 9.7.2, passing a user-controlled update such as MyModel.updateOne(filter, req.body) can exploit Mongoose upda…
- CVE-2026-72749MEDIUMCVSS 6.5EG 6.52026-08-11
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the Edit Fields (Set) node. The node assigns output fields via a dot-notation path setter without restricting the field name, allowing an authenticated…
- CVE-2026-71437MEDIUMCVSS 6.5EG 6.52026-08-06
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.5.0 until 11.16.1, Mermaid Architecture Diagrams are vulnerable to prototype pollution when a diagram defines a group w…
- CVE-2026-14574MEDIUMCVSS 6.5EG 6.52026-08-05
In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` recursively merges preference values without rejecting prototype-related keys (`__proto__`, `constructor`, `prototype`). B…
- CVE-2026-67314MEDIUMCVSS 6.5EG 6.52026-08-01
axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpers/resolveConfig.js). When an application is already affected by a separate prototype-poll…
- CVE-2026-42041MEDIUMCVSS 6.5EG 6.52026-04-24
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution to silently suppress all HTTP…
- CVE-2025-57324MEDIUMCVSS 6.5EG 6.52025-09-24
parse is a package designed to parse JavaScript SDK. A Prototype Pollution vulnerability in the SingleInstanceStateController.initializeState function of parse version 5.3.0 and before allows attackers to inject properties on Object.protot…
- CVE-2025-57320MEDIUMCVSS 6.5EG 6.52025-09-24
json-schema-editor-visual is a package that provides jsonschema editor. A Prototype Pollution vulnerability in the setData and deleteData function of json-schema-editor-visual versions thru 1.1.1 allows attackers to inject or delete proper…
- CVE-2025-57351MEDIUMCVSS 6.5EG 6.52025-09-24
A prototype pollution vulnerability exists in the ts-fns package versions prior to 13.0.7, where insufficient validation of user-provided keys in the assign function allows attackers to manipulate the Object.prototype chain. By leveraging …
- CVE-2025-57348MEDIUMCVSS 6.5EG 6.52025-09-24
The node-cube package (prior to version 5.0.0) contains a vulnerability in its handling of prototype chain initialization, which could allow an attacker to inject properties into the prototype of built-in objects. This issue, categorized u…
- CVE-2025-57354MEDIUMCVSS 6.5EG 6.52025-09-24
A vulnerability exists in the 'counterpart' library for Node.js and the browser due to insufficient sanitization of user-controlled input in translation key processing. The affected versions prior to 0.18.6 allow attackers to manipulate th…
- CVE-2024-45815MEDIUMCVSS 6.5EG 6.52024-09-17
Backstage is an open framework for building developer portals. A malicious actor with authenticated access to a Backstage instance with the catalog backend plugin installed is able to interrupt the service using a specially crafted query t…
- CVE-2024-39853MEDIUMCVSS 6.5EG 6.52024-07-01
adolph_dudu ratio-swiper 0.0.2 was discovered to contain a prototype pollution via the function parse. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
- CVE-2024-39000MEDIUMCVSS 6.5EG 6.52024-07-01
adolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function parse. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
- CVE-2024-38997MEDIUMCVSS 6.5EG 6.52024-07-01
adolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function extendDefaults. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary prope…
- CVE-2024-21509MEDIUMCVSS 6.5EG 6.52024-04-10
Versions of the package mysql2 before 3.9.4 are vulnerable to Prototype Poisoning due to insecure results object creation and improper user input sanitization passed through parserFn in text_parser.js and binary_parser.js.
- CVE-2023-26920MEDIUMCVSS 6.5EG 6.52023-12-12
fast-xml-parser before 4.1.2 allows __proto__ for Prototype Pollution.
- CVE-2023-26136MEDIUMCVSS 6.5EG 6.52023-07-01
Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are…
- CVE-2022-25645MEDIUMCVSS 6.5EG 6.52022-05-01
All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks for prototype pollution by validating if the top-level path contains __proto__, constructor or protorype. By crafting a m…
- CVE-2021-23771MEDIUMCVSS 6.5EG 6.52022-03-17
This affects all versions of package notevil; all versions of package argencoders-notevil. It is vulnerable to Sandbox Escape leading to Prototype pollution. The package fails to restrict access to the main context, allowing an attacker to…
- CVE-2021-23700MEDIUMCVSS 6.5EG 6.52021-12-10
All versions of package merge-deep2 are vulnerable to Prototype Pollution via the mergeDeep() function.
- CVE-2021-23663MEDIUMCVSS 6.5EG 6.52021-12-10
All versions of package sey are vulnerable to Prototype Pollution via the deepmerge() function.
- CVE-2021-23561MEDIUMCVSS 6.5EG 6.52021-12-10
All versions of package comb are vulnerable to Prototype Pollution via the deepMerge() function.
- CVE-2020-7770MEDIUMCVSS 6.5EG 6.52020-11-12
This affects the package json8 before 1.0.3. The function adds in the target object the property specified in the path, however it does not properly check the key being set, leading to a prototype pollution.
- CVE-2018-3721MEDIUMCVSS 6.5EG 6.52018-06-07
lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Object" via __proto__, …
- CVE-2026-54306MEDIUMCVSS 6.4EG 6.42026-06-16
n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, a prototype pollution vulnerability allowed a crafted public webhook payload to inject attacker-controlled fields into workflow data during internal object cop…
- CVE-2025-62374MEDIUMCVSS 6.4EG 6.42025-10-14
Parse Javascript SDK provides access to the powerful Parse Server backend from your JavaScript app. Prior to 7.0.0, injection of malicious payload allows attacker to remotely execute arbitrary code. ParseObject.fromJSON, ParseObject.pin, …
- CVE-2026-86536MEDIUMCVSS 6.3EG 6.32026-10-02
Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift all JS bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.…
- CVE-2026-91860MEDIUMCVSS 6.3EG 6.32026-09-30
A prototype pollution vulnerability exists in the deep merge helpers of Vaadin Charts and Vaadin Component Base. Merging an object the application does not control into a chart configuration or into a component's i18n property writes onto …
- CVE-2026-92781MEDIUMCVSS 6.3EG 6.32026-09-16
Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the unflatten helper that processes builder.userAttributes query parameters without prototype guards. Attackers can craft preview links…
- CVE-2026-78179MEDIUMCVSS 6.3EG 6.32026-08-24
A vulnerability was identified in rexrainbow phaser3-rex-notes up to 1.80.17. This vulnerability affects the function SetValue of the file plugins/utils/object/SetValue.js of the component BehaviorTree Blackboard Data Interface. Such manip…
- CVE-2026-16151MEDIUMCVSS 6.3EG 6.32026-07-18
A vulnerability has been found in CartoDB carto-api-client 0.5.29. This impacts the function addFilter of the file src/filters.ts. Such manipulation of the argument column leads to improperly controlled modification of object prototype att…
- CVE-2026-16150MEDIUMCVSS 6.3EG 6.32026-07-18
A vulnerability was found in RobinHerbots Inputmask up to 5.0.9. Affected by this issue is the function extendDefaults/extendDefinitions/extendAliases in the library lib/dependencyLibs/extend.js of the component Internal Deep Merge Helper.…
- CVE-2026-16008MEDIUMCVSS 6.3EG 6.32026-07-17
A security vulnerability has been detected in sagold json-schema-library 11.5.0/11.5.1. This impacts the function parsePropertyDependencies of the file src/keywords/propertyDependencies.ts. The manipulation leads to improperly controlled m…
- CVE-2026-15702MEDIUMCVSS 6.3EG 6.32026-07-14
A security vulnerability has been detected in tamagui up to 2.3.0. This affects the function updateConfig of the file code/core/web/src/config.ts. Such manipulation leads to improperly controlled modification of object prototype attributes…
Map vulnerabilities like CWE-1321 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1321 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →