CWE-1321— Improperly Controlled Modification of Object Prototype Attributes (Prototype Pollution)
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.— MITRE CWE catalog
622 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1321page 5 of 13
- CVE-2026-54639HIGHCVSS 8.8EG 8.82026-06-24
Style Dictionary, a build system for creating cross-platform styles, has a prototype pollution vulnerability starting in version 4.3.0 and prior to version 5.4.4. Impact users have: direct usage of `convertTokenData(tokens, { output: 'obje…
- CVE-2026-42232HIGHCVSS 8.8EG 8.82026-05-04
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via the XML Node leading to RC…
- CVE-2026-42231HIGHCVSS 8.8EG 8.82026-05-04
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the xml2js library used to parse XML request bodies in n8n's webhook handler allowed prototype pollution via a crafted XML payloa…
- CVE-2026-33696HIGHCVSS 8.8EG 8.82026-03-25
n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with permission to create or modify workflows could exploit a prototype pollution vulnerability in the XML and the GS…
- CVE-2026-25047HIGHCVSS 8.8EG 8.82026-01-29
deepHas provides a test for the existence of a nested object key and optionally returns that key. A prototype pollution vulnerability exists in version 1.0.7 of the deephas npm package that allows an attacker to modify global object behavi…
- CVE-2025-55164HIGHCVSS 8.8EG 8.82025-08-12
content-security-policy-parser parses content security policy directives. A prototype pollution vulnerability exists in versions 0.5.0 and earlier, wherein if a policy name is called __proto__, one can override the Object prototype. This i…
- CVE-2025-8101HIGHCVSS 8.8EG 8.82025-07-25
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Linkify (linkifyjs) allows XSS Targeting HTML Attributes and Manipulating User-Controlled Variables.This issue affects Linkify: from…
- CVE-2025-5150HIGHCVSS 8.8EG 8.82025-05-25
A vulnerability was found in docarray up to 0.40.1. It has been rated as critical. Affected by this issue is the function __getitem__ of the file /docarray/data/torch_dataset.py of the component Web API. The manipulation leads to improperl…
- CVE-2024-38992HIGHCVSS 8.8EG 8.82024-07-01
airvertco frappejs v0.0.11 was discovered to contain a prototype pollution via the function registerView. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
- CVE-2024-38991HIGHCVSS 8.8EG 8.82024-07-01
akbr patch-into v1.0.1 was discovered to contain a prototype pollution via the function patchInto. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
- CVE-2024-24293HIGHCVSS 8.8EG 8.82024-05-20
A Prototype Pollution issue in MiguelCastillo @bit/loader v.10.0.3 allows an attacker to execute arbitrary code via the M function e argument in index.js.
- CVE-2023-32305HIGHCVSS 8.8EG 8.82023-05-12
aiven-extras is a PostgreSQL extension. Versions prior to 1.1.9 contain a privilege escalation vulnerability, allowing elevation to superuser inside PostgreSQL databases that use the aiven-extras package. The vulnerability leverages missin…
- CVE-2023-23917HIGHCVSS 8.8EG 8.82023-02-23
A prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an attacker to a RCE under the admin account. Any user can create their own server in your cloud and become an admin so this vulnerability could affec…
- CVE-2022-2200HIGHCVSS 8.8EG 8.82022-12-22
If an object prototype was corrupted by an attacker, they would have been able to set undesired attributes on a JavaScript object, leading to privileged code execution. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunder…
- CVE-2022-1802HIGHCVSS 8.8EG 8.82022-12-22
If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context. This vulnerability affects Firefox …
- CVE-2022-1529HIGHCVSS 8.8EG 8.82022-12-22
An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScript object, leading to prototype pollution and ultimately attacker-controlled JavaScript executing in the privileged par…
- CVE-2021-43852HIGHCVSS 8.8EG 8.82022-01-04
OroPlatform is a PHP Business Application Platform. In affected versions by sending a specially crafted request, an attacker could inject properties into existing JavaScript language construct prototypes, such as objects. Later this inject…
- CVE-2021-20089HIGHCVSS 8.8EG 8.82021-04-23
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in purl 2.3.2 allows a malicious user to inject properties into Object.prototype.
- CVE-2021-20086HIGHCVSS 8.8EG 8.82021-04-23
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-bbq 1.2.1 allows a malicious user to inject properties into Object.prototype.
- CVE-2021-20085HIGHCVSS 8.8EG 8.82021-04-23
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in backbone-query-parameters 0.4.0 allows a malicious user to inject properties into Object.prototype.
- CVE-2021-20083HIGHCVSS 8.8EG 8.82021-04-23
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-plugin-query-object 2.2.3 allows a malicious user to inject properties into Object.prototype.
- CVE-2021-20088HIGHCVSS 8.8EG 8.82021-04-23
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in mootools-more 1.6.0 allows a malicious user to inject properties into Object.prototype.
- CVE-2021-20087HIGHCVSS 8.8EG 8.82021-04-23
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-deparam 0.5.1 allows a malicious user to inject properties into Object.prototype.
- CVE-2021-20084HIGHCVSS 8.8EG 8.82021-04-23
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-sparkle 1.5.2-beta allows a malicious user to inject properties into Object.prototype.
- CVE-2019-10808HIGHCVSS 8.8EG 8.82020-03-11
utilitify prior to 1.0.3 allows modification of object properties. The merge method could be tricked into adding or modifying properties of the Object.prototype.
- CVE-2019-17316HIGHCVSS 8.8EG 8.82019-10-07
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Import module by a Regular user.
- CVE-2019-9061HIGHCVSS 8.8EG 8.82019-03-26
An issue was discovered in CMS Made Simple 2.2.8. In the module ModuleManager (in the file action.installmodule.php), it is possible to reach an unserialize call with untrusted input and achieve authenticated object injection by using the …
- CVE-2018-19296HIGHCVSS 8.8EG 8.82018-11-16
PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.
- CVE-2018-11135HIGHCVSS 8.8EG 8.82018-05-31
The script '/adminui/error_details.php' in the Quest KACE System Management Appliance 8.0.318 allows authenticated users to conduct PHP object injection attacks.
- CVE-2026-94646HIGHCVSS 8.7EG 8.72026-10-02
Uncaught exception, Improper validation of specified quantity in input, Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift nodejs bindings. This issue affects Apache …
- CVE-2026-86535HIGHCVSS 8.7EG 8.72026-10-02
Loop with unreachable exit condition ('infinite loop'), Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift NodeJS bindings with TJSONProtocol. This issue affects Apac…
- CVE-2026-44494HIGHCVSS 8.7EG 8.72026-05-29
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's depende…
- CVE-2024-12556HIGHCVSS 8.7EG 8.72025-04-08
Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal.
- CVE-2020-11066HIGHCVSS 8.7EG 8.72020-05-14
In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, calling unserialize() on malicious user-submitted content can lead to modification of dynamically-determined object …
- CVE-2026-48795HIGHCVSS 8.6EG 8.62026-06-30
AdonisJS is a TypeScript-first web framework. From 10.1.3 until 10.1.5 and 11.0.3, AdonisJS @adonisjs/bodyparser incompletely fixed CVE-2026-25754 because nested multipart field payloads such as user.__proto__.polluted and constructor.prot…
- CVE-2026-41690HIGHCVSS 8.6EG 8.62026-05-08
18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Versions prior to 3.9.3 allow an unauthenticated HTTP client to pollute Object.prototype in the Node.js process hostin…
- CVE-2026-34622HIGHCVSS 8.6EG 8.62026-04-14
Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code exe…
- CVE-2025-8083HIGHCVSS 8.6EG 8.62025-12-12
The Preset configuration https://v2.vuetifyjs.com/en/features/presets feature of Vuetify is vulnerable to Prototype Pollution https://cheatsheetseries.owasp.org/cheatsheets/Prototype_Pollution_Prevention_Cheat_Sheet.html due to the i…
- CVE-2025-57350HIGHCVSS 8.6EG 8.62025-09-24
The csvtojson package, a tool for converting CSV data to JSON with customizable parsing capabilities, contains a prototype pollution vulnerability in versions prior to 2.0.10. This issue arises due to insufficient sanitization of nested he…
- CVE-2024-32866HIGHCVSS 8.6EG 8.62024-04-23
Conform, a type-safe form validation library, allows the parsing of nested objects in the form of `object.property`. Due to an improper implementation of this feature in versions prior to 1.1.1, an attacker can exploit the feature to trigg…
- CVE-2022-25354HIGHCVSS 8.6EG 8.62022-03-17
The package set-in before 2.0.3 are vulnerable to Prototype Pollution via the setIn method, as it allows an attacker to merge object prototypes into it. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-28273](https:…
- CVE-2021-23452HIGHCVSS 8.6EG 8.62021-10-20
This affects all versions of package x-assign. The global proto object can be polluted using the __proto__ object.
- CVE-2021-23442HIGHCVSS 8.6EG 8.62021-09-17
This affects all versions of package @cookiex/deep. The global proto object can be polluted using the __proto__ object.
- CVE-2020-28450HIGHCVSS 8.6EG 8.62021-02-04
This affects all versions of package decal. The vulnerability is in the extend function.
- CVE-2020-28449HIGHCVSS 8.6EG 8.62021-02-04
This affects all versions of package decal. The vulnerability is in the set function.
- CVE-2026-73654HIGHCVSS 8.5EG 8.52026-08-13
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 3.3.8 until 4.5.6, the PUT /api/v1/runs/:runId/metadata endpoint passes attacker-controlled operation.key values to new JSONHeroPath(operation…
- CVE-2026-54312HIGHCVSS 8.5EG 8.52026-06-16
n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via the Microsoft SQL node by supplying a crafted value as th…
- CVE-2025-68130HIGHCVSS 8.5EG 8.52025-12-16
tRPC allows users to build and consume fully typesafe APIs without schemas or code generation. Starting in version 10.27.0 and prior to versions 10.45.3 and 11.8.0, a A prototype pollution vulnerability exists in `@trpc/server`'s `formData…
- CVE-2020-7774HIGHCVSS 7.3EG 8.52020-11-17
The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.
- CVE-2026-97151HIGHCVSS 8.4EG 8.42026-09-24
mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a document. Converting a crafted .docx file allows an attacker to add arbitrary properties to Object.prototype. In 1.11.0 throug…
Map vulnerabilities like CWE-1321 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1321 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →