CWE-1321— Improperly Controlled Modification of Object Prototype Attributes (Prototype Pollution)
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.— MITRE CWE catalog
622 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1321page 6 of 13
- CVE-2025-58280HIGHCVSS 8.4EG 8.42025-09-05
Vulnerability of exposing object heap addresses in the Ark eTS module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2023-0163HIGHCVSS 8.4EG 8.42024-11-26
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Mozilla Convict. This allows an attacker to inject attributes that are used in other components, or to override existing attributes…
- CVE-2026-101909HIGHCVSS 8.3EG 8.32026-09-28
Axios is a promise-based HTTP client for the browser and Node.js. From 0.28.0 until 0.34.0 and 1.15.1 until 1.20.0, ToFormData processes inherited serialization options and visitor properties supplied through prototype pollution. A separat…
- CVE-2026-82404HIGHCVSS 8.3EG 8.32026-09-02
TOON is a compact, human-readable serialization of JSON data for LLM prompts. Prior to 2.3.1, decoding attacker-controlled TOON with a __proto__, constructor, or prototype key wrote through the object prototype chain instead of creating an…
- CVE-2026-55451HIGHCVSS 8.3EG 8.32026-08-20
gettext-converter provides gettext resource conversion utilities for JavaScript. Prior to 1.3.3, js2i18next() in lib/js2i18next.js splits nested translation keys using options.keyseparator, whose default value consists of two number signs,…
- CVE-2025-62381HIGHCVSS 8.3EG 8.32025-10-15
sveltekit-superforms makes SvelteKit forms a pleasure to use. sveltekit-superforms v2.27.3 and prior are susceptible to a prototype pollution vulnerability within the parseFormData function of formData.js. An attacker can inject string and…
- CVE-2024-36577HIGHCVSS 8.3EG 8.32024-06-17
apphp js-object-resolver < 3.1.1 is vulnerable to Prototype Pollution via Module.setNestedProperty.
- CVE-2022-31106HIGHCVSS 8.3EG 8.32022-06-28
Underscore.deep is a collection of Underscore mixins that operate on nested objects. Versions of `underscore.deep` prior to version 0.5.3 are vulnerable to a prototype pollution vulnerability. An attacker can craft a malicious payload and …
- CVE-2026-107701HIGHCVSS 8.2EG 8.22026-10-08
dot-access through 1.0.0 contains a prototype pollution vulnerability that allows attackers to modify Object.prototype by supplying a crafted dotted path to set(). Attackers controlling the path, such as through user-supplied field names, …
- CVE-2026-104852HIGHCVSS 8.2EG 8.22026-10-05
GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 12.0.1, the GraphQL Tools utils package's mergeDeep function follows inherited properties while recursively merging source objects and does not…
- CVE-2026-63376HIGHCVSS 8.2EG 8.22026-09-03
toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in lib/compiler.js can be tricked by a table path such as a.b.y.__proto__.__proto__, allowing traversal from a scalar value into Number.prototype and Obje…
- CVE-2026-44490HIGHCVSS 8.2EG 8.22026-05-29
Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-side prototype-pollution gadgets. When Object.prototype is polluted by an upstream dependency in the same process (e.g. lo…
- CVE-2026-46509HIGHCVSS 8.2EG 8.22026-05-28
deepobj provides get, set, delete deep objects in javascript. Prior to 1.0.3, prototype pollution is possible when property paths contain __proto__/constructor/prototype. The property path must not be exposed as user input. This vulnerabil…
- CVE-2026-44483HIGHCVSS 8.2EG 8.22026-05-27
RVF (formerly Remix Validated Form) provides easy form validation and state management for React. From 6.0.0 to before 6.0.4 and 7.0.2, setPath in @rvf/set-get (used by @rvf/core to flatten incoming form data into a nested object) does not…
- CVE-2026-45325HIGHCVSS 8.2EG 8.22026-05-18
Gestor de Oferta is a web application for managing mobility service offerings. Prior to 20260509.0340.15, @tmlmobilidade/utils has a prototype pollution vulnerability in setValueAtPath() in packages/utils/src/generic/value-at-path.ts becau…
- CVE-2026-45302HIGHCVSS 8.2EG 8.22026-05-18
parse-nested-form-data is a tiny node module for parsing FormData by name into objects and arrays. Prior to version 1.0.1, parseFormData() walks bracket and dot-notation FormData field names into nested objects without filtering reserved p…
- CVE-2026-46510HIGHCVSS 8.2EG 8.22026-05-18
form-data-objectizer converts FormData to object. Prior to 1.0.1, form-data-objectizer walks bracket-notation form keys (e.g. name[sub]) into nested objects without filtering __proto__, constructor, or prototype. A single HTTP form field w…
- CVE-2026-8657HIGHCVSS 8.2EG 8.22026-05-16
Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Prototype Pollution via the jsondiffpatch.patch() and jsondiffpatch/formatters/jsonpatch.patch() APIs. An attacker can perform prototype pollution by supplying crafted de…
- CVE-2024-21489HIGHCVSS 8.2EG 8.22024-10-01
Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to missing check if the attribute resolves to the object prototype.
- CVE-2024-21529HIGHCVSS 8.2EG 8.22024-09-11
Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user input sanitization. This vulnerability allows the attacker to inject malicious object property using the built-in Objec…
- CVE-2024-21512HIGHCVSS 8.2EG 8.22024-05-29
Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitization passed to fields and tables when using nestTables.
- CVE-2023-26158HIGHCVSS 8.2EG 8.22023-12-08
All versions of the package mockjs are vulnerable to Prototype Pollution via the Util.extend function due to missing check if the attribute resolves to the object prototype. By adding or modifying attributes of an object prototype, it is p…
- CVE-2023-26133HIGHCVSS 8.2EG 8.22023-06-12
All versions of the package progressbar.js are vulnerable to Prototype Pollution via the function extend() in the file utils.js.
- CVE-2023-28427HIGHCVSS 8.2EG 8.22023-03-28
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 24.0.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potent…
- CVE-2023-28103HIGHCVSS 8.2EG 8.22023-03-28
matrix-react-sdk is a Matrix chat protocol SDK for React Javascript. In certain configurations, data sent by remote servers containing special strings in key locations could cause modifications of the `Object.prototype`, disrupting matrix-…
- CVE-2022-36060HIGHCVSS 8.2EG 8.22023-03-28
matrix-react-sdk is a Matrix chat protocol SDK for React Javascript. Events sent with special strings in key places can temporarily disrupt or impede the matrix-react-sdk from functioning properly, such as by causing room or event tile cra…
- CVE-2022-36059HIGHCVSS 8.2EG 8.22023-03-28
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 19.4.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potent…
- CVE-2022-25878HIGHCVSS 8.2EG 8.22022-05-27
The package protobufjs before 6.11.3 are vulnerable to Prototype Pollution which can allow an attacker to add/modify properties of the Object.prototype. This vulnerability can occur in multiple ways: 1. by providing untrusted user input to…
- CVE-2022-21824HIGHCVSS 8.2EG 8.22022-02-24
Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one property as the first par…
- CVE-2021-23470HIGHCVSS 8.2EG 8.22022-02-04
This affects the package putil-merge before 3.8.0. The merge() function does not check the values passed into the argument. An attacker can supply a malicious value by adjusting the value to include the constructor property. Note: This vul…
- CVE-2023-26102HIGHCVSS 7.5EG 8.22023-02-24
All versions of the package rangy are vulnerable to Prototype Pollution when using the extend() function in file rangy-core.js.The function uses recursive merge which can lead an attacker to modify properties of the Object.prototype
- CVE-2026-81994HIGHCVSS 6.3EG 8.22026-09-08
Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access …
- CVE-2026-105858HIGHCVSS 8.1EG 8.12026-10-06
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a crafted request to the public first-register operation can execute code remotely when local authe…
- CVE-2026-85625HIGHCVSS 8.1EG 8.12026-09-04
sift (sift.js) 17.1.3 enumerates query keys with for...in, which walks the object prototype chain, and dispatches any matched operator key including $where. The $where operation compiles a string value into a function using new Function un…
- CVE-2026-72769HIGHCVSS 8.1EG 8.12026-08-11
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engine. An authenticated user able to create or edit a workflow expression can abuse the engine's array-element access to obtain a re…
- CVE-2026-55388HIGHCVSS 8.1EG 8.12026-06-18
piscina is a node.js worker pool implementation. Prior to 6.0.0-rc.2, 5.2.0, and 4.9.3, piscina's constructor and run() paths read the filename option via plain member access. Both reads fall through the prototype chain when the caller's o…
- CVE-2024-39016HIGHCVSS 8.1EG 8.12024-07-01
che3vinci c3/utils-1 1.0.131 was discovered to contain a prototype pollution via the function assign. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
- CVE-2024-36583HIGHCVSS 8.1EG 8.12024-06-17
A Prototype Pollution issue in byondreal accessor <= 1.0.0 allows an attacker to execute arbitrary code via @byondreal/accessor/index.
- CVE-2024-29651HIGHCVSS 8.1EG 8.12024-05-20
A Prototype Pollution issue in API Dev Tools json-schema-ref-parser v.11.0.0 and v.11.1.0 allows a remote attacker to execute arbitrary code via the bundle()`, `parse()`, `resolve()`, `dereference() functions.
- CVE-2022-39357HIGHCVSS 8.1EG 8.12022-10-26
Winter is a free, open-source content management system based on the Laravel PHP framework. The Snowboard framework in versions 1.1.8, 1.1.9, and 1.2.0 is vulnerable to prototype pollution in the main Snowboard class as well as its plugin …
- CVE-2020-36604HIGHCVSS 8.1EG 8.12022-09-23
hoek before 8.5.1 and 9.x before 9.0.3 allows prototype poisoning in the clone function.
- CVE-2022-24802HIGHCVSS 8.1EG 8.12022-04-01
deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. deepmerge-ts is vulnerable to Prototype Pollution via file deepmerge.ts, function defaultMergeRecords(). This issue has been patched in ver…
- CVE-2022-23624HIGHCVSS 8.1EG 8.12022-02-07
Frourio-express is a minimal full stack framework, for TypeScript. Frourio-express users who uses frourio-express version prior to v0.26.0 and integration with class-validator through `validators/` folder are subject to a input validation …
- CVE-2022-23623HIGHCVSS 8.1EG 8.12022-02-07
Frourio is a full stack framework, for TypeScript. Frourio users who uses frourio version prior to v0.26.0 and integration with class-validator through `validators/` folder are subject to a input validation vulnerability. Validators do not…
- CVE-2020-7644HIGHCVSS 8.1EG 8.12020-04-28
fun-map through 3.3.1 is vulnerable to Prototype Pollution. The function assocInM could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.
- CVE-2022-2625HIGHCVSS 8.0EG 8.02022-08-18
A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and…
- CVE-2025-57820HIGHCVSS 7.9EG 7.92025-08-26
Svelte devalue is a utility library. Prior to version 5.3.2, a string passed to devalue.parse could represent an object with a __proto__ property and devalue.parse does not check that an index is numeric. This could result in assigning pro…
- CVE-2026-27212HIGHCVSS 7.8EG 7.82026-02-21
Swiper is a free and mobile touch slider with hardware accelerated transitions and native behavior. Versions 6.5.1 through 12.1.1 have a Prototype pollution vulnerability. The vulnerability resides in line 94 of shared/utils.mjs, where the…
- CVE-2023-45811HIGHCVSS 7.8EG 7.82023-10-17
Synchrony deobfuscator is a javascript cleaner & deobfuscator. A `__proto__` pollution vulnerability exists in versions before v2.4.4. Successful exploitation could lead to arbitrary code execution. A `__proto__` pollution vulnerability e…
- CVE-2023-30533HIGHCVSS 7.8EG 7.82023-04-24
SheetJS Community Edition before 0.19.3 allows Prototype Pollution via a crafted file. In other words. 0.19.2 and earlier are affected, whereas 0.19.3 and later are unaffected.
Map vulnerabilities like CWE-1321 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1321 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →