CWE-1321— Improperly Controlled Modification of Object Prototype Attributes (Prototype Pollution)
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.— MITRE CWE catalog
622 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1321page 12 of 13
- CVE-2020-7748MEDIUMCVSS 5.6EG 5.62020-10-20
This affects the package @tsed/core before 5.65.7. This vulnerability relates to the deepExtend function which is used as part of the utils directory. Depending on if user input is provided, an attacker can overwrite and pollute the object…
- CVE-2020-15366MEDIUMCVSS 5.6EG 5.62020-07-15
An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code by prototype pollution. (While untrusted schemas are recomme…
- CVE-2020-7598MEDIUMCVSS 5.6EG 5.62020-03-11
minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
- CVE-2026-30785MEDIUMCVSS 5.5EG 5.52026-03-05
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Insufficient Computational Effort vulnerability in rustdesk-client RustDesk Client rustdesk, hbb_common on Windows, MacOS,…
- CVE-2025-31475MEDIUMCVSS 5.5EG 5.52025-04-07
tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where the addOrUpdate function, used for applying custom texts, did not properly validate input. This allowed…
- CVE-2021-4278MEDIUMCVSS 5.5EG 5.52022-12-25
A vulnerability classified as problematic has been found in cronvel tree-kit up to 0.6.x. This affects an unknown part. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). Up…
- CVE-2021-4245MEDIUMCVSS 5.5EG 5.52022-12-15
A vulnerability classified as problematic has been found in chbrown rfc6902. This affects an unknown part of the file pointer.ts. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollu…
- CVE-2026-23929MEDIUMCVSS 5.4EG 5.42026-08-18
Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuery's unsafe element creation that travers…
- CVE-2026-70610MEDIUMCVSS 5.4EG 5.42026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.4, objects copied across the contextBridge boundary from untrusted content could carry…
- CVE-2021-23432MEDIUMCVSS 5.4EG 5.42021-08-24
This affects all versions of package mootools. This is due to the ability to pass untrusted input to Object.merge()
- CVE-2021-23408MEDIUMCVSS 5.4EG 5.42021-07-21
This affects the package com.graphhopper:graphhopper-web-bundle before 3.2, from 4.0-pre1 and before 4.0. The URL parser could be tricked into adding or modifying properties of Object.prototype using a constructor or __proto__ payload.
- CVE-2026-12209MEDIUMCVSS 5.3EG 5.32026-06-15
A security vulnerability has been detected in RubyLouvre avalon up to 2.2.10. The impacted element is an unknown function of the file src/filters/index.js of the component Template Filter Handler. Such manipulation leads to improperly cont…
- CVE-2026-12208MEDIUMCVSS 5.3EG 5.32026-06-15
A weakness has been identified in jsonata-js jsonata up to 2.2.0. The affected element is the function createFrame of the file src/jsonata.js of the component Function Binding Frame System. This manipulation causes improperly controlled mo…
- CVE-2026-44489MEDIUMCVSS 5.3EG 5.32026-05-29
Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created by utils.merge() (e.g., config.proxy) are still constructed as plain {} with Object.prototype in their chain. The setPro…
- CVE-2026-44292MEDIUMCVSS 5.3EG 5.32026-05-13
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated message constructors copied enumerable properties from a provided properties object without filtering the __proto__ key…
- CVE-2026-2950MEDIUMCVSS 5.3EG 5.32026-03-31
Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards agai…
- CVE-2026-33672MEDIUMCVSS 5.3EG 5.32026-03-26
Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Because the object inherits from `Object.prototype`, sp…
- CVE-2026-31865MEDIUMCVSS 5.3EG 5.32026-03-18
Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server communication. Prior to version 1.4.27, an Elysia cookie can be overridden by prototype pollution , eg. `__proto__`. This iss…
- CVE-2025-13465MEDIUMCVSS 5.3EG 5.32026-01-21
Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion …
- CVE-2025-64718MEDIUMCVSS 5.3EG 5.32025-11-13
js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse un…
- CVE-2025-57353MEDIUMCVSS 5.3EG 5.32025-09-24
The Runtime components of messageformat package for Node.js before 3.0.2 contain a prototype pollution vulnerability. Due to insufficient validation of nested message keys during the processing of message data, an attacker can manipulate t…
- CVE-2025-57352MEDIUMCVSS 5.3EG 5.32025-09-24
A vulnerability exists in the 'min-document' package prior to version 2.19.0, stemming from improper handling of namespace operations in the removeAttributeNS method. By processing malicious input involving the __proto__ property, an attac…
- CVE-2023-0842MEDIUMCVSS 5.3EG 5.32023-04-05
xml2js version 0.4.23 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the __proto__ property to be edited.
- CVE-2022-42743MEDIUMCVSS 5.3EG 5.32022-11-03
deep-parse-json version 1.0.2 allows an external attacker to edit or add new properties to an object. This is possible because the application does not correctly validate the incoming JSON keys, thus allowing the '__proto__' property to be…
- CVE-2022-41714MEDIUMCVSS 5.3EG 5.32022-11-03
fastest-json-copy version 1.0.1 allows an external attacker to edit or add new properties to an object. This is possible because the application does not correctly validate the incoming JSON keys, thus allowing the '__proto__' property to …
- CVE-2022-41713MEDIUMCVSS 5.3EG 5.32022-11-03
deep-object-diff version 1.1.0 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the '__proto__' property to be edi…
- CVE-2020-7643MEDIUMCVSS 5.3EG 5.32020-04-23
paypal-adaptive through 0.4.2 manipulation of JavaScript objects resulting in Prototype Pollution. The PayPal function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
- CVE-2020-7618MEDIUMCVSS 5.3EG 5.32020-04-07
sds through 3.2.0 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of the 'Object.prototype' by abusing the 'set' function located in 'js/set.js'.
- CVE-2020-7616MEDIUMCVSS 5.3EG 5.32020-04-07
express-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tricked into adding or modifying properties of the `Object.prototype`. Exploitation of this vulnerability requires creatio…
- CVE-2020-7639MEDIUMCVSS 5.3EG 5.32020-04-06
eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.
- CVE-2020-7638MEDIUMCVSS 5.3EG 5.32020-04-06
confinit through 0.3.0 is vulnerable to Prototype Pollution.The 'setDeepProperty' function could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.
- CVE-2020-7637MEDIUMCVSS 5.3EG 5.32020-04-06
class-transformer before 0.3.1 allow attackers to perform Prototype Pollution. The classToPlainFromExist function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
- CVE-2020-7608MEDIUMCVSS 5.3EG 5.32020-03-16
yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload.
- CVE-2020-7600MEDIUMCVSS 5.3EG 5.32020-03-12
querymen prior to 2.1.4 allows modification of object properties. The parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. This could be abused for Prototype Pollution attacks.
- CVE-2026-42077MEDIUMCVSS 5.2EG 5.22026-05-04
Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a prototype pollution vulnerability in the mailbox store module allows attackers to modify the behavior of all JavaScript objects by injecting malicious …
- CVE-2024-2495MEDIUMCVSS 5.2EG 5.22024-03-15
Cryptographic key vulnerability encoded in the FriendlyWrt firmware affecting version 2022-11-16.51b3d35. This vulnerability could allow an attacker to compromise the confidentiality and integrity of encrypted data.
- CVE-2026-104183MEDIUMCVSS 5.1EG 5.12026-10-01
stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, Assembler materializes object properties with plain assignment, so an input key named __proto__ invokes the …
- CVE-2026-81887MEDIUMCVSS 5.1EG 5.12026-08-31
Livewire is a full-stack framework for Laravel. From 3.0.0-beta.1 until 3.8.3 and 4.3.4, the dot-notated query-string parser in js/plugins/history/index.js, including fromQueryString() and insertDotNotatedValueIntoData(), accepts the __pro…
- CVE-2026-66922MEDIUMCVSS 5.1EG 5.12026-07-28
Pivotick used plain JavaScript objects as lookup tables indexed by caller-controlled graph node identifiers in its tree-layout and cycle-detection components. Node identifiers matching properties inherited from Object.prototype, such as c…
- CVE-2026-57439MEDIUMCVSS 5.0EG 5.02026-07-08
CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.2.0, the Series Chart operation accepts __proto__ as a key while parsing user-supplied CSV, allowing prototype pollution that can be chained with …
- CVE-2024-14020MEDIUMCVSS 5.0EG 5.02026-01-07
A weakness has been identified in carboneio carbone up to fbcd349077ad0e8748be73eab2a82ea92b6f8a7e. This impacts an unknown function of the file lib/input.js of the component Formatter Handler. Executing a manipulation can lead to improper…
- CVE-2026-24766MEDIUMCVSS 4.9EG 4.92026-01-28
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, an authenticated user with org-level-creator permissions can exploit prototype pollution in the `/api/v2/meta/connection/test` endpoint, causing all datab…
- CVE-2026-56763MEDIUMCVSS 4.8EG 4.82026-07-11
Hono before 4.12.7 allows __proto__ key in parseBody with dot option enabled, permitting specially crafted form field names to create objects with __proto__ properties. When parsed results are merged into regular JavaScript objects using u…
- CVE-2026-59876MEDIUMCVSS 4.8EG 4.82026-07-08
protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 until 8.6.5, the protobufjs Text Format extension parsed string-keyed map entries using ordinary property assignment, allowing a map entry with key __proto…
- CVE-2026-48819MEDIUMCVSS 4.8EG 4.82026-07-01
Hey API is an ecosystem for turning API specifications into production-ready code. Prior to 0.97.3, dist/clients/core/params.ts ships a runtime template copied into generated SDKs as params.gen.ts, and buildClientParams writes unknown slot…
- CVE-2026-33916MEDIUMCVSS 4.7EG 4.72026-03-27
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolvePartial()` in the Handlebars runtime resolves partial names via a plain property lookup on `options.partials` without g…
- CVE-2026-53592MEDIUMCVSS 4.6EG 4.62026-07-20
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A Prototype Pollution condition in the `getQueryParam` function `/public/js/main.js` and was addressed in version 1.8.139 by blocking URL query keys matchin…
- CVE-2024-34698MEDIUMCVSS 4.6EG 4.62024-05-14
FreeScout is a free, self-hosted help desk and shared mailbox. Versions of FreeScout prior to 1.8.139 contain a Prototype Pollution vulnerability in the `/public/js/main.js` source file. The Prototype Pollution arises because the `getQuery…
- CVE-2021-32807MEDIUMCVSS 4.4EG 4.42021-07-30
The module `AccessControl` defines security policies for Python code used in restricted code within Zope applications. Restricted code is any code that resides in Zope's object database, such as the contents of `Script (Python)` objects. T…
- CVE-2026-97724MEDIUMCVSS 4.3EG 4.32026-09-25
A prototype pollution vulnerability in Software Mansion React Native Worklets before 0.12.2 allows an attacker-controlled object containing a __proto__ property to modify the prototype of an object created during serialization in clonePlai…
Map vulnerabilities like CWE-1321 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1321 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →