CWE-1321— Improperly Controlled Modification of Object Prototype Attributes (Prototype Pollution)
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.— MITRE CWE catalog
622 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1321page 2 of 13
- CVE-2024-39011CRITICALCVSS 9.8EG 9.82024-07-30
Prototype Pollution in chargeover redoc v2.0.9-rc.69 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via the function mergeObjects.
- CVE-2024-39010CRITICALCVSS 9.8EG 9.82024-07-30
chase-moskal snapstate v0.0.9 was discovered to contain a prototype pollution via the function attemptNestedProperty. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary …
- CVE-2024-38986CRITICALCVSS 9.8EG 9.82024-07-30
Prototype Pollution in 75lb deep-merge 1.1.1 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via merge methods of lodash to merge objects.
- CVE-2024-38984CRITICALCVSS 9.8EG 9.82024-07-30
Prototype Pollution in lukebond json-override 0.2.0 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) via the __proto__ property.
- CVE-2024-36572CRITICALCVSS 9.8EG 9.82024-07-30
Prototype pollution in allpro form-manager 0.7.4 allows attackers to run arbitrary code and cause other impacts via the functions setDefaults, mergeBranch, and Object.setObjectValue.
- CVE-2024-39014CRITICALCVSS 9.8EG 9.82024-07-01
ahilfoley cahil/utils v2.3.2 was discovered to contain a prototype pollution via the function set. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
- CVE-2024-39013CRITICALCVSS 9.8EG 9.82024-07-01
2o3t-utility v0.1.2 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
- CVE-2024-38996CRITICALCVSS 9.8EG 9.82024-07-01
ag-grid-community v31.3.2 and ag-grid-enterprise v31.3.2 were discovered to contain a prototype pollution via the _.mergeDeep function. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via in…
- CVE-2024-38993CRITICALCVSS 9.8EG 9.82024-07-01
rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function empty. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
- CVE-2024-36573CRITICALCVSS 9.8EG 9.82024-06-17
almela obx before v.0.0.4 has a Prototype Pollution issue which allows arbitrary code execution via the obx/build/index.js:656), reduce (@almela/obx/build/index.js:470), Object.set (obx/build/index.js:269) component.
- CVE-2024-36582CRITICALCVSS 9.8EG 9.82024-06-17
alexbinary object-deep-assign 1.0.11 is vulnerable to Prototype Pollution via the extend() method of Module.deepAssign (/src/index.js)
- CVE-2024-36580CRITICALCVSS 9.8EG 9.82024-06-17
A Prototype Pollution issue in cdr0 sg 1.0.10 allows an attacker to execute arbitrary code.
- CVE-2024-30564CRITICALCVSS 9.8EG 9.82024-04-18
An issue inandrei-tatar nora-firebase-common between v.1.0.41 and v.1.12.2 allows a remote attacker to execute arbitrary code via a crafted script to the updateState parameter of the updateStateInternal method.
- CVE-2024-29650CRITICALCVSS 9.8EG 9.82024-03-25
An issue in @thi.ng/paths v.5.1.62 and before allows a remote attacker to execute arbitrary code via the mutIn and mutInManyUnsafe components.
- CVE-2024-27307CRITICALCVSS 9.8EG 9.82024-03-06
JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a malicious expression can use the transform operator to override properties on the `Object` constructor and prototype. Th…
- CVE-2023-46308CRITICALCVSS 9.8EG 9.82024-01-03
In Plotly plotly.js before 2.25.2, plot API calls have a risk of __proto__ being polluted in expandObjectPaths or nestedProperty.
- CVE-2023-45827CRITICALCVSS 9.8EG 9.82023-11-06
Dot diver is a lightweight, powerful, and dependency-free TypeScript utility library that provides types and functions to work with object paths in dot notation. In versions prior to 1.0.2 there is a Prototype Pollution vulnerability in th…
- CVE-2023-38894CRITICALCVSS 9.8EG 9.82023-08-16
A Prototype Pollution issue in Cronvel Tree-kit v.0.7.4 and before allows a remote attacker to execute arbitrary code via the extend function.
- CVE-2021-26505CRITICALCVSS 9.8EG 9.82023-08-11
Prototype pollution vulnerability in MrSwitch hello.js version 1.18.6, allows remote attackers to execute arbitrary code via hello.utils.extend function.
- CVE-2023-3186CRITICALCVSS 9.8EG 9.82023-07-17
The Popup by Supsystic WordPress plugin before 1.10.19 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties into Object.prototype.
- CVE-2023-3696CRITICALCVSS 9.8EG 9.82023-07-17
Prototype Pollution in GitHub repository automattic/mongoose prior to 7.3.4.
- CVE-2023-36665CRITICALCVSS 9.8EG 9.82023-07-05
"protobuf.js (aka protobufjs) 6.10.0 through 7.x before 7.2.5 allows Prototype Pollution, a different vulnerability than CVE-2022-25878. A user-controlled protobuf message can be used by an attacker to pollute the prototype of Object.proto…
- CVE-2023-36475CRITICALCVSS 9.8EG 9.82023-06-28
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 5.5.2 and 6.2.1, an attacker can use a prototype pollution sink to trigger a remote code execution through the MongoD…
- CVE-2023-2972CRITICALCVSS 9.8EG 9.82023-05-30
Prototype Pollution in GitHub repository antfu/utils prior to 0.7.3.
- CVE-2023-30363CRITICALCVSS 9.8EG 9.82023-04-26
vConsole v3.15.0 was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions in core.ts.
- CVE-2022-39396CRITICALCVSS 9.8EG 9.82022-11-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 4.10.18, and prior to 5.3.1 on the 5.X branch, are vulnerable to Remote Code Execution via prototype pollution. An at…
- CVE-2022-37623CRITICALCVSS 9.8EG 9.82022-10-31
Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the shimPath variable in resolve-shims.js.
- CVE-2022-37621CRITICALCVSS 9.8EG 9.82022-10-28
Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the fullPath variable in resolve-shims.js.
- CVE-2022-37598CRITICALCVSS 9.8EG 9.82022-10-20
Prototype pollution vulnerability in function DEFNODE in ast.js in mishoo UglifyJS 3.13.2 via the name variable in ast.js. NOTE: the vendor considers this an invalid report.
- CVE-2022-37602CRITICALCVSS 9.8EG 9.82022-10-14
Prototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key variable in grunt-karma.js.
- CVE-2022-37601CRITICALCVSS 9.8EG 9.82022-10-12
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
- CVE-2022-37614CRITICALCVSS 9.8EG 9.82022-10-12
Prototype pollution vulnerability in function enable in mockery.js in mfncooper mockery commit 822f0566fd6d72af8c943ae5ca2aa92e516aa2cf via the key variable in mockery.js.
- CVE-2022-37611CRITICALCVSS 9.8EG 9.82022-10-12
Prototype pollution vulnerability in tschaub gh-pages 3.1.0 via the partial variable in util.js.
- CVE-2022-37617CRITICALCVSS 9.8EG 9.82022-10-11
Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the k variable in resolve-shims.js.
- CVE-2022-37609CRITICALCVSS 9.8EG 9.82022-10-11
Prototype pollution vulnerability in beautify-web js-beautify 1.13.7 via the name variable in options.js.
- CVE-2022-37616CRITICALCVSS 9.8EG 9.82022-10-11
A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this repor…
- CVE-2022-37265CRITICALCVSS 9.8EG 9.82022-09-20
Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js.
- CVE-2022-37258CRITICALCVSS 9.8EG 9.82022-09-16
Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the packageName variable in npm-convert.js.
- CVE-2022-37264CRITICALCVSS 9.8EG 9.82022-09-15
Prototype pollution vulnerability in stealjs steal 2.2.4 via the optionName variable in main.js.
- CVE-2022-37266CRITICALCVSS 9.8EG 9.82022-09-15
Prototype pollution vulnerability in function extend in babel.js in stealjs steal 2.2.4 via the key variable in babel.js.
- CVE-2022-37257CRITICALCVSS 9.8EG 9.82022-09-15
Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVersion variable in npm-convert.js.
- CVE-2022-2564CRITICALCVSS 9.8EG 9.82022-07-28
Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6.
- CVE-2021-40663CRITICALCVSS 9.8EG 9.82022-06-30
deep.assign npm package 0.0.0-alpha.0 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution').
- CVE-2022-1295CRITICALCVSS 9.8EG 9.82022-04-11
Prototype Pollution in GitHub repository alvarotrigo/fullpage.js prior to 4.0.2.
- CVE-2022-26260CRITICALCVSS 9.8EG 9.82022-03-22
Simple-Plist v1.3.0 was discovered to contain a prototype pollution vulnerability via .parse().
- CVE-2021-44906CRITICALCVSS 9.8EG 9.82022-03-17
Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
- CVE-2021-44908CRITICALCVSS 9.8EG 9.82022-03-17
SailsJS Sails.js <=1.4.0 is vulnerable to Prototype Pollution via controller/load-action-modules.js, function loadActionModules().
- CVE-2022-22912CRITICALCVSS 9.8EG 9.82022-02-17
Prototype pollution vulnerability via .parse() in Plist before v3.0.4 allows attackers to cause a Denial of Service (DoS) and may lead to remote code execution.
- CVE-2021-23594CRITICALCVSS 9.8EG 9.82022-01-10
All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.
- CVE-2021-23543CRITICALCVSS 9.8EG 9.82022-01-10
All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.
Map vulnerabilities like CWE-1321 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1321 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →