CWE-1321— Improperly Controlled Modification of Object Prototype Attributes (Prototype Pollution)
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.— MITRE CWE catalog
622 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1321page 3 of 13
- CVE-2021-23450CRITICALCVSS 9.8EG 9.82021-12-17
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
- CVE-2021-3815CRITICALCVSS 9.8EG 9.82021-12-08
utils.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
- CVE-2021-3918CRITICALCVSS 9.8EG 9.82021-11-13
json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
- CVE-2021-23449CRITICALCVSS 9.8EG 9.82021-10-18
This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to execution of arbitrary code on the host machine.
- CVE-2021-3666CRITICALCVSS 9.8EG 9.82021-09-13
body-parser-xml is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
- CVE-2021-3645CRITICALCVSS 9.8EG 9.82021-09-10
merge is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
- CVE-2021-3766CRITICALCVSS 9.8EG 9.82021-09-06
objection.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
- CVE-2021-3757CRITICALCVSS 9.8EG 9.82021-09-02
immer is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
- CVE-2021-25953CRITICALCVSS 9.8EG 9.82021-07-14
Prototype pollution vulnerability in 'putil-merge' versions1.0.0 through 3.6.6 allows attacker to cause a denial of service and may lead to remote code execution.
- CVE-2021-25952CRITICALCVSS 9.8EG 9.82021-07-07
Prototype pollution vulnerability in ‘just-safe-set’ versions 1.0.0 through 2.2.1 allows an attacker to cause a denial of service and may lead to remote code execution.
- CVE-2021-25949CRITICALCVSS 9.8EG 9.82021-06-10
Prototype pollution vulnerability in 'set-getter' version 0.1.0 allows an attacker to cause a denial of service and may lead to remote code execution.
- CVE-2021-25948CRITICALCVSS 9.8EG 9.82021-06-10
Prototype pollution vulnerability in 'expand-hash' versions 0.1.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
- CVE-2021-25947CRITICALCVSS 9.8EG 9.82021-06-03
Prototype pollution vulnerability in 'nestie' versions 0.0.0 through 1.0.0 allows an attacker to cause a denial of service and may lead to remote code execution.
- CVE-2021-26707CRITICALCVSS 9.8EG 9.82021-06-02
The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-…
- CVE-2021-25945CRITICALCVSS 9.8EG 9.82021-05-26
Prototype pollution vulnerability in 'js-extend' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
- CVE-2021-25946CRITICALCVSS 9.8EG 9.82021-05-25
Prototype pollution vulnerability in `nconf-toml` versions 0.0.1 through 0.0.2 allows an attacker to cause a denial of service and may lead to remote code execution.
- CVE-2021-25944CRITICALCVSS 9.8EG 9.82021-05-25
Prototype pollution vulnerability in 'deep-defaults' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.
- CVE-2021-25943CRITICALCVSS 9.8EG 9.82021-05-14
Prototype pollution vulnerability in '101' versions 1.0.0 through 1.6.3 allows an attacker to cause a denial of service and may lead to remote code execution.
- CVE-2021-25941CRITICALCVSS 9.8EG 9.82021-05-14
Prototype pollution vulnerability in 'deep-override' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
- CVE-2021-23383CRITICALCVSS 9.8EG 9.82021-05-04
The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.
- CVE-2021-25928CRITICALCVSS 9.8EG 9.82021-04-26
Prototype pollution vulnerability in 'safe-obj' versions 1.0.0 through 1.0.2 allows an attacker to cause a denial of service and may lead to remote code execution.
- CVE-2021-25927CRITICALCVSS 9.8EG 9.82021-04-26
Prototype pollution vulnerability in 'safe-flat' versions 2.0.0 through 2.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
- CVE-2021-25916CRITICALCVSS 9.8EG 9.82021-03-16
Prototype pollution vulnerability in 'patchmerge' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
- CVE-2021-25915CRITICALCVSS 9.8EG 9.82021-03-09
Prototype pollution vulnerability in 'changeset' versions 0.0.1 through 0.2.5 allows an attacker to cause a denial of service and may lead to remote code execution.
- CVE-2021-25914CRITICALCVSS 9.8EG 9.82021-03-01
Prototype pollution vulnerability in 'object-collider' versions 1.0.0 through 1.0.3 allows attacker to cause a denial of service and may lead to remote code execution.
- CVE-2021-25913CRITICALCVSS 9.8EG 9.82021-02-08
Prototype pollution vulnerability in 'set-or-get' version 1.0.0 through 1.2.10 allows an attacker to cause a denial of service and may lead to remote code execution.
- CVE-2021-25912CRITICALCVSS 9.8EG 9.82021-02-02
Prototype pollution vulnerability in 'dotty' versions 0.0.1 through 0.1.0 allows attackers to cause a denial of service and may lead to remote code execution.
- CVE-2020-28276CRITICALCVSS 9.8EG 9.82020-12-29
Prototype pollution vulnerability in 'deep-set' versions 1.0.0 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
- CVE-2020-7788CRITICALCVSS 9.8EG 9.82020-12-11
This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the cont…
- CVE-2020-28271CRITICALCVSS 9.8EG 9.82020-11-12
Prototype pollution vulnerability in 'deephas' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.
- CVE-2020-28270CRITICALCVSS 9.8EG 9.82020-11-12
Prototype pollution vulnerability in 'object-hierarchy-access' versions 0.2.0 through 0.32.0 allows attacker to cause a denial of service and may lead to remote code execution.
- CVE-2020-28269CRITICALCVSS 9.8EG 9.82020-11-12
Prototype pollution vulnerability in 'field' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
- CVE-2020-8158CRITICALCVSS 9.8EG 9.82020-09-18
Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks.
- CVE-2019-0230CRITICALCVSS 9.8EG 9.82020-09-14
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
- CVE-2020-7727CRITICALCVSS 9.8EG 9.82020-09-01
All versions of package gedi are vulnerable to Prototype Pollution via the set function.
- CVE-2020-7726CRITICALCVSS 9.8EG 9.82020-09-01
All versions of package safe-object2 are vulnerable to Prototype Pollution via the setter function.
- CVE-2020-7725CRITICALCVSS 9.8EG 9.82020-09-01
All versions of package worksmith are vulnerable to Prototype Pollution via the setValue function.
- CVE-2020-7724CRITICALCVSS 9.8EG 9.82020-09-01
All versions of package tiny-conf are vulnerable to Prototype Pollution via the set function.
- CVE-2020-7723CRITICALCVSS 9.8EG 9.82020-09-01
All versions of package promisehelpers are vulnerable to Prototype Pollution via the insert function.
- CVE-2020-7722CRITICALCVSS 9.8EG 9.82020-09-01
All versions of package nodee-utils are vulnerable to Prototype Pollution via the deepSet function.
- CVE-2020-7721CRITICALCVSS 9.8EG 9.82020-09-01
All versions of package node-oojs are vulnerable to Prototype Pollution via the setPath function.
- CVE-2020-7720CRITICALCVSS 9.8EG 9.82020-09-01
The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.
- CVE-2020-7719CRITICALCVSS 9.8EG 9.82020-09-01
Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function.
- CVE-2020-7718CRITICALCVSS 9.8EG 9.82020-09-01
All versions of package gammautils are vulnerable to Prototype Pollution via the deepSet and deepMerge functions.
- CVE-2020-7717CRITICALCVSS 9.8EG 9.82020-09-01
All versions of package dot-notes are vulnerable to Prototype Pollution via the create function.
- CVE-2020-7716CRITICALCVSS 9.8EG 9.82020-09-01
All versions of package deeps are vulnerable to Prototype Pollution via the set function.
- CVE-2020-7715CRITICALCVSS 9.8EG 9.82020-09-01
All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function.
- CVE-2020-7714CRITICALCVSS 9.8EG 9.82020-09-01
All versions of package confucious are vulnerable to Prototype Pollution via the set function.
- CVE-2020-7713CRITICALCVSS 9.8EG 9.82020-09-01
All versions of package arr-flatten-unflatten are vulnerable to Prototype Pollution via the constructor.
- CVE-2020-7708CRITICALCVSS 9.8EG 9.82020-08-18
The package irrelon-path before 4.7.0; the package @irrelon/path before 4.7.0 are vulnerable to Prototype Pollution via the set, unSet, pushVal and pullVal functions.
Map vulnerabilities like CWE-1321 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1321 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →