CWE-1321— Improperly Controlled Modification of Object Prototype Attributes (Prototype Pollution)
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.— MITRE CWE catalog
622 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1321page 4 of 13
- CVE-2020-7707CRITICALCVSS 9.8EG 9.82020-08-18
The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.
- CVE-2020-7706CRITICALCVSS 9.8EG 9.82020-08-18
The package connie-lang before 0.1.1 are vulnerable to Prototype Pollution in the configuration language library used by connie.
- CVE-2020-7704CRITICALCVSS 9.8EG 9.82020-08-17
The package linux-cmdline before 1.0.1 are vulnerable to Prototype Pollution via the constructor.
- CVE-2020-7703CRITICALCVSS 9.8EG 9.82020-08-17
All versions of package nis-utils are vulnerable to Prototype Pollution via the setValue function.
- CVE-2020-7702CRITICALCVSS 9.8EG 9.82020-08-17
All versions of package templ8 are vulnerable to Prototype Pollution via the parse function.
- CVE-2020-7701CRITICALCVSS 9.8EG 9.82020-08-14
madlib-object-utils before 0.1.7 is vulnerable to Prototype Pollution via setValue.
- CVE-2020-7700CRITICALCVSS 9.8EG 9.82020-08-14
All versions of phpjs are vulnerable to Prototype Pollution via parse_str.
- CVE-2019-19919CRITICALCVSS 9.8EG 9.82019-12-20
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code …
- CVE-2019-14379CRITICALCVSS 9.8EG 9.82019-07-29
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
- CVE-2018-3753CRITICALCVSS 9.8EG 9.82018-07-03
The utilities function in all versions <= 1.0.0 of the merge-objects node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker ad…
- CVE-2021-23702CRITICALCVSS 7.6EG 9.82022-02-18
The package object-extend from 0.0.0 are vulnerable to Prototype Pollution via object-extend.
- CVE-2022-25904CRITICALCVSS 7.5EG 9.82022-12-20
All versions of package safe-eval are vulnerable to Prototype Pollution which allows an attacker to add or modify properties of the Object.prototype.Consolidate when using the function safeEval. This is because the function uses vm variabl…
- CVE-2021-23373CRITICALCVSS 7.5EG 9.82022-07-25
All versions of package set-deep-prop are vulnerable to Prototype Pollution via the main functionality.
- CVE-2021-23574CRITICALCVSS 7.5EG 9.82021-12-24
All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn and the set functions. This is an incomplete fix of [CVE-2020-28442](https://snyk.io/vuln/SNYK-JS-JSDATA-1023655).
- CVE-2020-28462CRITICALCVSS 7.3EG 9.82022-07-25
This affects all versions of package ion-parser. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can be exploited further depending on the c…
- CVE-2021-23448CRITICALCVSS 6.5EG 9.82021-10-11
All versions of package config-handler are vulnerable to Prototype Pollution when loading config files.
- CVE-2021-23421CRITICALCVSS 5.6EG 9.82021-08-11
All versions of package merge-change are vulnerable to Prototype Pollution via the utils.set function.
- CVE-2020-7617CRITICALCVSS 4.4EG 9.82020-04-02
ini-parser through 0.0.2 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of Object.prototype using a '__proto__' payload.
- CVE-2023-1717CRITICALCVSS 9.6EG 9.62023-11-01
Prototype pollution in bitrix/templates/bitrix24/components/bitrix/menu/left_vertical/script.js in Bitrix24 22.0.300 allows remote attackers to execute arbitrary JavaScript code in the victim’s browser, and possibly execute arbitrary PH…
- CVE-2026-104849CRITICALCVSS 9.5EG 9.52026-10-02
Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from a caller-supplied options object in pool.run(task, options) without requiring an own property, so a polluted Object.prototype.fil…
- CVE-2026-104848CRITICALCVSS 9.5EG 9.52026-10-02
Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.1, Tinypool constructs ThreadPool.options from a normal options object and reads the execArgv and env worker options in dist/index.js, allowing values inherited …
- CVE-2026-78207CRITICALCVSS 9.4EG 9.42026-08-24
exceljs through 4.4.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSON with a malicious __proto_…
- CVE-2025-62410CRITICALCVSS 9.4EG 9.42025-10-15
In versions before 20.0.2, it was found that --disallow-code-generation-from-strings is not sufficient for isolating untrusted JavaScript in happy-dom. The untrusted script and the rest of the application still run in the same Isolate/proc…
- CVE-2026-105844CRITICALCVSS 9.3EG 9.32026-10-06
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an unauthenticated user can submit prototype-sensitive field paths when @payloadcms/plug…
- CVE-2026-25521CRITICALCVSS 9.3EG 9.32026-02-04
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to before 2.0.39, a prototype pollution vulnerability exists in locutus. Despite a previous fix that attempted to mitigat…
- CVE-2025-13158CRITICALCVSS 9.3EG 9.32025-12-26
Prototype pollution vulnerability in apidoc-core versions 0.2.0 and all subsequent versions allows remote attackers to modify JavaScript object prototypes via malformed data structures, including the “define” property processed by the …
- CVE-2026-102992CRITICALCVSS 9.2EG 9.22026-09-30
piscina is a node.js worker pool implementation. Prior to 4.9.4, 5.3.2, and 6.0.0-rc.5, Piscina stores ThreadPool.options in src/index.ts as a plain object that inherits from Object.prototype. Applications with a separate prototype-polluti…
- CVE-2026-61534CRITICALCVSS 9.1EG 9.12026-09-11
Yayson is a library for serializing and reading JSON API data in JavaScript. Prior to 4.3.0, Store and LegacyStore use attacker-controlled JSON:API type, id, and relationship names as keys in plain-object lookup tables in src/yayson/store.…
- CVE-2026-48170CRITICALCVSS 9.1EG 9.12026-06-22
`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation whose `value` object contains a key like `"__proto__.someProp"`. After one such patch, `Object.prototyp…
- CVE-2026-48714CRITICALCVSS 9.1EG 9.12026-06-15
i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. In versions prior to 3.9.7, the missingKeyHandler blocked the literal request-body keys __proto__, constructor, and p…
- CVE-2026-48713CRITICALCVSS 9.1EG 9.12026-06-15
Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missing translation keys (e.g. via i18next-http-middleware's missingKeyHandler exposed to untrusted input). Backend.writeFil…
- CVE-2026-53609CRITICALCVSS 9.1EG 9.12026-06-12
ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, `apos.util.set()` traverses dot-notation paths without sanitizing `__proto__`, allowing an authenticated editor to write arbitrary v…
- CVE-2026-42264CRITICALCVSS 9.1EG 9.12026-05-08
Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via dir…
- CVE-2026-42044CRITICALCVSS 9.1EG 9.12026-04-24
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependen…
- CVE-2026-34221CRITICALCVSS 9.1EG 9.12026-03-31
MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, a prototype pollution vulnerability exists in the Utils.merge helper used internally by MikroORM whe…
- CVE-2025-25014CRITICALCVSS 9.1EG 9.12025-05-06
A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.
- CVE-2024-57077CRITICALCVSS 9.1EG 9.12025-02-05
The latest version of utils-extend (1.0.8) is vulnerable to Prototype Pollution through the entry function(s) lib.extend. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the global pro…
- CVE-2024-48910CRITICALCVSS 9.1EG 9.12024-10-31
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2.
- CVE-2024-37287CRITICALCVSS 9.1EG 9.12024-08-13
A flaw allowing arbitrary code execution was discovered in Kibana. An attacker with access to ML and Alerting connector features, as well as write access to internal ML indices can trigger a prototype pollution vulnerability, ultimately le…
- CVE-2021-42581CRITICALCVSS 9.1EG 9.12022-05-10
Prototype poisoning in function mapObjIndexed in Ramda 0.27.0 and earlier allows attackers to compromise integrity or availability of application via supplying a crafted object (that contains an own property "__proto__") as an argument to …
- CVE-2021-41097CRITICALCVSS 9.1EG 9.12021-09-27
aurelia-path is part of the Aurelia platform and contains utilities for path manipulation. There is a prototype pollution vulnerability in aurelia-path before version 1.1.7. The vulnerability exposes Aurelia application that uses `aurelia-…
- CVE-2021-28860CRITICALCVSS 9.1EG 9.12021-05-03
In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This will …
- CVE-2021-27582CRITICALCVSS 9.1EG 9.12021-02-23
org/mitre/oauth2/web/OAuthConfirmationController.java in the OpenID Connect server implementation for MITREid Connect through 1.3.3 contains a Mass Assignment (aka Autobinding) vulnerability. This arises due to unsafe usage of the @ModelAt…
- CVE-2019-10744CRITICALCVSS 9.1EG 9.12019-07-26
Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
- CVE-2022-23631CRITICALCVSS 9.0EG 9.02022-02-09
superjson is a program to allow JavaScript expressions to be serialized to a superset of JSON. In versions prior to 1.8.1 superjson allows input to run arbitrary code on any server using superjson input without prior authentication or know…
- CVE-2021-43787CRITICALCVSS 9.0EG 9.02021-11-29
Nodebb is an open source Node.js based forum software. In affected versions a prototype pollution vulnerability in the uploader module allowed a malicious user to inject arbitrary data (i.e. javascript) into the DOM, theoretically allowing…
- CVE-2019-11358CRITICALCVSS 6.1EG 9.02019-04-20
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could e…
- CVE-2026-106448HIGHCVSS 8.9EG 8.92026-10-06
StableLib is a stable library of useful TypeScript and JavaScript code. Prior to 2.0.4, the @stablelib/cbor CBOR map decoding path creates ordinary JavaScript objects and assigns attacker-controlled keys with bracket assignment. A map key …
- CVE-2025-27597HIGHCVSS 8.9EG 8.92025-03-07
Vue I18n is the internationalization plugin for Vue.js. @intlify/message-resolver and @intlify/vue-i18n-core are vulnerable to Prototype Pollution through the entry function: handleFlatJson. An attacker can supply a payload with Object.pro…
- CVE-2026-18420HIGHCVSS 8.8EG 8.82026-08-20
Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endp…
Map vulnerabilities like CWE-1321 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1321 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →