CWE-1321— Improperly Controlled Modification of Object Prototype Attributes (Prototype Pollution)
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.— MITRE CWE catalog
622 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1321page 11 of 13
- CVE-2026-15699MEDIUMCVSS 6.3EG 6.32026-07-14
A vulnerability was identified in spencermountain compromise up to 14.15.1. Affected is the function nlp.extend of the file src/API/extend.js of the component Public Root API. The manipulation of the argument plugin leads to improperly con…
- CVE-2026-15698MEDIUMCVSS 6.3EG 6.32026-07-14
A vulnerability was determined in kofrasa mingo up to 7.2.1. This impacts the function update/updateOne/updateMany of the component Update API. Executing a manipulation of the argument Set can lead to improperly controlled modification of …
- CVE-2026-15697MEDIUMCVSS 6.3EG 6.32026-07-14
A vulnerability was found in svgdotjs svg.js up to 3.2.5. This affects the function EventTarget.on of the file svgdotjs/svg.js of the component npm Package API. Performing a manipulation results in improperly controlled modification of obj…
- CVE-2026-15598MEDIUMCVSS 6.3EG 6.32026-07-13
A weakness has been identified in antv layout 2.0.0. This impacts the function setNestedValue in the library lib/util/object.js. Executing a manipulation of the argument path can lead to improperly controlled modification of object prototy…
- CVE-2026-15538MEDIUMCVSS 6.3EG 6.32026-07-13
A weakness has been identified in primefaces primereact up to 10.9.8. This issue affects the function ObjectUtils.mutateFieldData of the file components/lib/utils/ObjectUtils.js of the component API. This manipulation of the argument Field…
- CVE-2026-15195MEDIUMCVSS 6.3EG 6.32026-07-09
A weakness has been identified in apidevtools json-schema-ref-parser up to 15.3.5. This impacts the function Refs.set/Pointer.set in the library lib/pointer.ts. Executing a manipulation can lead to improperly controlled modification of obj…
- CVE-2026-54756MEDIUMCVSS 6.3EG 6.32026-07-01
Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities. In versions prior to 4.12.18, Jodit.configure(options) — and the internal ConfigMerge / ConfigProto helpers — merged user-supplied op…
- CVE-2026-55886MEDIUMCVSS 6.3EG 6.32026-06-18
Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities. Versions prior to 4.12.26 are vulnerable to Prototype Pollution through Jodit.modules.Helpers.set(chain, value, obj), which walks the dot…
- CVE-2026-34626MEDIUMCVSS 6.3EG 6.32026-04-14
Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary file sys…
- CVE-2024-39018MEDIUMCVSS 6.3EG 6.32024-07-01
harvey-woo cat5th/key-serializer v0.2.5 was discovered to contain a prototype pollution via the function "query". This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary prop…
- CVE-2024-39001MEDIUMCVSS 6.3EG 6.32024-07-01
ag-grid-enterprise v31.3.2 was discovered to contain a prototype pollution via the component _ModuleSupport.jsonApply. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary…
- CVE-2024-38987MEDIUMCVSS 6.3EG 6.32024-07-01
aofl cli-lib v3.14.0 was discovered to contain a prototype pollution via the component defaultsDeep. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
- CVE-2024-36574MEDIUMCVSS 6.3EG 6.32024-06-17
A Prototype Pollution issue in flatten-json 1.0.1 allows an attacker to execute arbitrary code via module.exports.unflattenJSON (flatten-json/index.js:42)
- CVE-2024-23339MEDIUMCVSS 6.3EG 6.32024-01-22
hoolock is a suite of lightweight utilities designed to maintain a small footprint when bundled. Starting in version 2.0.0 and prior to version 2.2.1, utility functions related to object paths (`get`, `set`, and `update`) did not block att…
- CVE-2021-4307MEDIUMCVSS 6.3EG 6.32023-01-07
A vulnerability was found in Yomguithereal Baobab up to 2.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to improperly controlled modification of object prototype a…
- CVE-2022-4742MEDIUMCVSS 6.3EG 6.32022-12-26
A vulnerability, which was classified as critical, has been found in json-pointer up to 0.6.1. Affected by this issue is the function set of the file index.js. The manipulation leads to improperly controlled modification of object prototyp…
- CVE-2021-4279MEDIUMCVSS 6.3EG 6.32022-12-25
A vulnerability has been found in Starcounter-Jack JSON-Patch up to 3.1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improperly controlled modification of object prototype attributes (…
- CVE-2020-36632MEDIUMCVSS 6.3EG 6.32022-12-25
A vulnerability, which was classified as critical, was found in hughsk flat up to 5.0.0. This affects the function unflatten of the file index.js. The manipulation leads to improperly controlled modification of object prototype attributes …
- CVE-2021-4264MEDIUMCVSS 6.3EG 6.32022-12-21
A vulnerability was found in LinkedIn dustjs up to 2.x and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improperly controlled modification of object prototype attributes ('proto…
- CVE-2020-36618MEDIUMCVSS 6.3EG 6.32022-12-19
A vulnerability classified as critical has been found in Furqan node-whois. Affected is an unknown function of the file index.coffee. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype p…
- CVE-2022-25296MEDIUMCVSS 6.3EG 6.32022-03-17
The package bodymen from 0.0.0 are vulnerable to Prototype Pollution via the handler function which could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload. **Note:** This vulnerability derives fr…
- CVE-2021-39227MEDIUMCVSS 6.2EG 6.22021-09-17
ZRender is a lightweight graphic library providing 2d draw for Apache ECharts. In versions prior to 5.2.1, using `merge` and `clone` helper methods in the `src/core/util.ts` module results in prototype pollution. It affects the popular dat…
- CVE-2026-65913MEDIUMCVSS 6.1EG 6.12026-07-23
DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute filtering by polluting Array.prototype properties. Attackers can set Array.prototype properties like onclick…
- CVE-2026-49459MEDIUMCVSS 6.1EG 6.12026-06-15
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attributes on an attacker-controlled <form> root when a descendant …
- CVE-2025-53626MEDIUMCVSS 6.1EG 6.12025-07-10
pdfme is a TypeScript-based PDF generator and React-based UI. The expression evaluation feature in pdfme 5.2.0 to 5.4.0 contains critical vulnerabilities allowing sandbox escape leading to XSS and prototype pollution attacks. This vulnerab…
- CVE-2023-3965MEDIUMCVSS 6.1EG 6.12023-10-20
The nsc theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticate…
- CVE-2023-3962MEDIUMCVSS 6.1EG 6.12023-10-20
The Winters theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthen…
- CVE-2023-3933MEDIUMCVSS 6.1EG 6.12023-10-20
The Your Journey theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions up to, and including, 1.9.8 due to insufficient input sanitization and output escaping. This makes it possible for una…
- CVE-2023-2582MEDIUMCVSS 6.1EG 6.12023-05-08
A prototype pollution vulnerability exists in Strikingly CMS which can result in reflected cross-site scripting (XSS) in affected applications and sites built with Strikingly. The vulnerability exists because of Strikingly JavaScript libra…
- CVE-2021-43956MEDIUMCVSS 6.1EG 6.12022-03-16
The jQuery deserialize library in Fisheye and Crucible before version 4.8.9 allowed remote attackers to to inject arbitrary HTML and/or JavaScript via a prototype pollution vulnerability.
- CVE-2022-23395MEDIUMCVSS 6.1EG 6.12022-03-02
jQuery Cookie 1.4.1 is affected by prototype pollution, which can lead to DOM cross-site scripting (XSS).
- CVE-2022-0432MEDIUMCVSS 6.1EG 6.12022-02-02
Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0.
- CVE-2020-7751MEDIUMCVSS 6.0EG 6.02020-10-26
pathval before version 1.1.1 is vulnerable to prototype pollution.
- CVE-2020-7709MEDIUMCVSS 6.0EG 6.02020-10-05
This affects the package json-pointer before 0.6.1. Multiple reference of object using slash is supported.
- CVE-2026-77083MEDIUMCVSS 5.9EG 5.92026-08-20
n8n is a workflow automation platform. In versions prior to 1.123.69, 2.33.4, and 2.34.1, the JavaScript Code node's VM sandbox did not freeze the sandbox's Function.prototype, allowing an authenticated user with the ability to create and …
- CVE-2025-62517MEDIUMCVSS 5.9EG 5.92025-10-23
Rollbar.js offers error tracking and logging from Javascript to Rollbar. In versions before 2.26.5 and from 3.0.0-alpha1 to before 3.0.0-beta5, there is a prototype pollution vulnerability in merge(). If application code calls rollbar.conf…
- CVE-2024-21528MEDIUMCVSS 5.9EG 5.92024-09-10
All versions of the package node-gettext are vulnerable to Prototype Pollution via the addTranslations() function in gettext.js due to improper user input sanitization.
- CVE-2024-36578MEDIUMCVSS 5.9EG 5.92024-06-17
akbr update 1.0.0 is vulnerable to Prototype Pollution via update/index.js.
- CVE-2024-34273MEDIUMCVSS 5.9EG 5.92024-05-16
njwt up to v0.4.0 was discovered to contain a prototype pollution in the Parser.prototype.parse method.
- CVE-2022-25871MEDIUMCVSS 5.9EG 5.92022-06-17
All versions of package querymen are vulnerable to Prototype Pollution if the parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. Note: This vulnerability derives from an incomplete …
- CVE-2021-23433MEDIUMCVSS 5.9EG 5.92021-11-19
The package algoliasearch-helper before 3.6.2 are vulnerable to Prototype Pollution due to use of the merge function in src/SearchParameters/index.jsSearchParameters._parseNumbers without any protection against prototype properties. Note t…
- CVE-2024-57708MEDIUMCVSS 5.7EG 5.72025-06-25
An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __proto__, and Object.assign components. NOTE: this is disputed by the Supplier who does not agree it is a prototype poll…
- CVE-2026-73647MEDIUMCVSS 5.6EG 5.62026-08-13
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the public extend() utility in ui/src/utils/extend/extend.js recursively copied attacker-controlled object keys during extend(true, targ…
- CVE-2021-23397MEDIUMCVSS 5.6EG 5.62022-07-25
All versions of package @ianwalter/merge are vulnerable to Prototype Pollution via the main (merge) function. Maintainer suggests using @generates/merger instead.
- CVE-2021-23760MEDIUMCVSS 5.6EG 5.62022-01-28
The package keyget from 0.0.0 are vulnerable to Prototype Pollution via the methods set, push, and at which could allow an attacker to cause a denial of service and may lead to remote code execution. **Note:** This vulnerability derives fr…
- CVE-2021-23417MEDIUMCVSS 5.6EG 5.62021-07-28
All versions of package deepmergefn are vulnerable to Prototype Pollution via deepMerge function.
- CVE-2021-23396MEDIUMCVSS 5.6EG 5.62021-06-17
All versions of package lutils are vulnerable to Prototype Pollution via the main (merge) function.
- CVE-2021-23328MEDIUMCVSS 5.6EG 5.62021-01-29
This affects all versions of package iniparserjs. This vulnerability relates when ini_parser.js is concentrating arrays. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program.
- CVE-2020-28460MEDIUMCVSS 5.6EG 5.62020-12-22
This affects the package multi-ini before 2.1.2. It is possible to pollute an object's prototype by specifying the constructor.proto object as part of an array. This is a bypass of CVE-2020-28448.
- CVE-2020-28448MEDIUMCVSS 5.6EG 5.62020-12-22
This affects the package multi-ini before 2.1.1. It is possible to pollute an object's prototype by specifying the proto object as part of an array.
Map vulnerabilities like CWE-1321 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1321 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →