CWE-1321— Improperly Controlled Modification of Object Prototype Attributes (Prototype Pollution)
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.— MITRE CWE catalog
622 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1321page 8 of 13
- CVE-2024-21505HIGHCVSS 7.5EG 7.52024-03-25
Versions of the package web3-utils before 4.2.1 are vulnerable to Prototype Pollution via the utility functions format and mergeDeep, due to insecure recursive merge. An attacker can manipulate an object's prototype, potentially leading to…
- CVE-2023-39296HIGHCVSS 7.5EG 7.52024-01-05
A prototype pollution vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to override existing attributes with ones that have incompatible type, which may lead…
- CVE-2023-45282HIGHCVSS 7.5EG 7.52023-10-06
In NASA Open MCT (aka openmct) before 3.1.0, prototype pollution can occur via an import action.
- CVE-2023-26139HIGHCVSS 7.5EG 7.52023-08-01
Versions of the package underscore-keypath from 0.0.11 are vulnerable to Prototype Pollution via the name argument of the setProperty() function. Exploiting this vulnerability is possible due to improper input sanitization which allows the…
- CVE-2023-26132HIGHCVSS 7.5EG 7.52023-06-10
Versions of the package dottie before 2.0.4 are vulnerable to Prototype Pollution due to insufficient checks, via the set() function and the current variable in the /dottie.js file.
- CVE-2023-26113HIGHCVSS 7.5EG 7.52023-03-18
Versions of the package collection.js before 6.8.1 are vulnerable to Prototype Pollution via the extend function in Collection.js/dist/node/iterators/extend.js.
- CVE-2023-26106HIGHCVSS 7.5EG 7.52023-03-06
All versions of the package dot-lens are vulnerable to Prototype Pollution via the set() function in index.js file.
- CVE-2023-26105HIGHCVSS 7.5EG 7.52023-02-28
All versions of the package utilities are vulnerable to Prototype Pollution via the _mix function.
- CVE-2022-24999HIGHCVSS 7.5EG 7.52022-11-26
qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated re…
- CVE-2022-25907HIGHCVSS 7.5EG 7.52022-08-09
The package ts-deepmerge before 2.0.2 are vulnerable to Prototype Pollution due to missing sanitization of the merge function.
- CVE-2022-21231HIGHCVSS 7.5EG 7.52022-06-24
All versions of package deep-get-set are vulnerable to Prototype Pollution via the 'deep' function. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-7715](https://security.snyk.io/vuln/SNYK-JS-DEEPGETSET-598666)
- CVE-2022-21213HIGHCVSS 7.5EG 7.52022-06-17
This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn mixes objects into the target object, recursively mixing existing child objects as well. In both c…
- CVE-2022-21190HIGHCVSS 7.5EG 7.52022-05-13
This affects the package convict before 6.2.3. This is a bypass of [CVE-2022-22143](https://security.snyk.io/vuln/SNYK-JS-CONVICT-2340604). The [fix](https://github.com/mozilla/node-convict/commit/3b86be087d8f14681a9c889d45da7fe3ad9cd880) …
- CVE-2022-25324HIGHCVSS 7.5EG 7.52022-05-06
All versions of package bignum are vulnerable to Denial of Service (DoS) due to a type-check exception in V8, when verifying the type of the second argument to the .powm function, V8 will crash regardless of Node try/catch blocks.
- CVE-2022-22143HIGHCVSS 7.5EG 7.52022-05-01
The package convict before 6.2.2 are vulnerable to Prototype Pollution via the convict function due to missing validation of parentKey. **Note:** This vulnerability derives from an incomplete fix of another [vulnerability](https://security…
- CVE-2022-24279HIGHCVSS 7.5EG 7.52022-04-15
The package madlib-object-utils before 0.1.8 are vulnerable to Prototype Pollution via the setValue method, as it allows an attacker to merge object prototypes into it. *Note:* This vulnerability derives from an incomplete fix of [CVE-2020…
- CVE-2022-25352HIGHCVSS 7.5EG 7.52022-03-17
The package libnested before 1.5.2 are vulnerable to Prototype Pollution via the set function in index.js. **Note:** This vulnerability derives from an incomplete fix for [CVE-2020-28283](https://security.snyk.io/vuln/SNYK-JS-LIBNESTED-105…
- CVE-2021-23597HIGHCVSS 7.5EG 7.52022-02-11
This affects the package fastify-multipart before 5.3.1. By providing a name=constructor property it is still possible to crash the application. **Note:** This is a bypass of CVE-2020-8136 (https://security.snyk.io/vuln/SNYK-JS-FASTIFYMULT…
- CVE-2021-23507HIGHCVSS 7.5EG 7.52022-02-04
The package object-path-set before 1.0.2 are vulnerable to Prototype Pollution via the setPath method, as it allows an attacker to merge object prototypes into it. *Note:* This vulnerability derives from an incomplete fix in https://securi…
- CVE-2021-23497HIGHCVSS 7.5EG 7.52022-02-04
This affects the package @strikeentco/set before 1.0.2. It allows an attacker to cause a denial of service and may lead to remote code execution. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/…
- CVE-2021-23460HIGHCVSS 7.5EG 7.52022-01-21
The package min-dash before 3.8.1 are vulnerable to Prototype Pollution via the set method due to missing enforcement of key types.
- CVE-2021-3805HIGHCVSS 7.5EG 7.52021-09-17
object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
- CVE-2021-32811HIGHCVSS 7.5EG 7.52021-08-02
Zope is an open-source web application server. Zope versions prior to versions 4.6.3 and 5.3 have a remote code execution security issue. In order to be affected, one must use Python 3 for one's Zope deployment, run Zope 4 below version 4.…
- CVE-2021-32736HIGHCVSS 7.5EG 7.52021-06-30
think-helper defines a set of helper functions for ThinkJS. In versions of think-helper prior to 1.1.3, the software receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, bu…
- CVE-2020-24939HIGHCVSS 7.5EG 7.52021-06-16
Prototype pollution in Stampit supermixer 1.0.3 allows an attacker to modify the prototype of a base object which can vary in severity depending on the implementation.
- CVE-2021-23329HIGHCVSS 7.5EG 7.52021-01-31
The package nested-object-assign before 1.0.4 are vulnerable to Prototype Pollution via the default function, as demonstrated by running the PoC below.
- CVE-2020-7771HIGHCVSS 7.5EG 7.52021-01-04
The package asciitable.js before 1.0.3 are vulnerable to Prototype Pollution via the main function.
- CVE-2020-7792HIGHCVSS 7.5EG 7.52020-12-11
This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn 'mixes objects into the target object, recursively mixing existing child objects as well'. In both…
- CVE-2020-28268HIGHCVSS 7.5EG 7.52020-11-15
Prototype pollution vulnerability in 'controlled-merge' versions 1.0.0 through 1.2.0 allows attacker to cause a denial of service and may lead to remote code execution.
- CVE-2020-7768HIGHCVSS 7.5EG 7.52020-11-11
The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.
- CVE-2020-7746HIGHCVSS 7.5EG 7.52020-10-29
This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. When the options are processed, the existing options (or the defaults options) are deeply merged with provided options. H…
- CVE-2020-7699HIGHCVSS 7.5EG 7.52020-07-30
This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP request can lead to denial of service or arbitrary code execution.
- CVE-2020-5258HIGHCVSS 7.5EG 7.52020-03-10
In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. A…
- CVE-2019-10768HIGHCVSS 7.5EG 7.52019-11-19
In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload.
- CVE-2019-16328HIGHCVSS 7.5EG 7.52019-10-03
In RPyC 4.1.x through 4.1.1, a remote attacker can dynamically modify object attributes to construct a remote procedure call that executes code for an RPyC service with default configuration settings.
- CVE-2019-10745HIGHCVSS 7.5EG 7.52019-08-20
assign-deep is vulnerable to Prototype Pollution in versions before 0.4.8 and version 1.0.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using either a constructor or a _proto_ payload.
- CVE-2021-23426HIGHCVSS 5.6EG 7.52021-09-01
This affects all versions of package Proto. It is possible to inject pollute the object property of an application using Proto by leveraging the merge function.
- CVE-2022-25862HIGHCVSS 4.0EG 7.52022-05-13
This affects the package sds from 0.0.0. The library could be tricked into adding or modifying properties of the Object.prototype by abusing the set function located in js/set.js. **Note:** This vulnerability derives from an incomplete fix…
- CVE-2026-67316HIGHCVSS 7.4EG 7.42026-08-01
axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a separate vulnerability or dependency. In the bodyless method aliases (axios.get(), axios.…
- CVE-2026-42035HIGHCVSS 7.4EG 7.42026-04-24
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadget exists in the Axios HTTP adapter (lib/adapters/http.js) that allows an attacker to inject arbitrary HTTP headers int…
- CVE-2026-42033HIGHCVSS 7.4EG 7.42026-04-24
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) silen…
- CVE-2020-8203HIGHCVSS 7.4EG 7.42020-07-15
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
- CVE-2026-78654HIGHCVSS 7.3EG 7.32026-08-25
A vulnerability has been found in cleverbrush framework and deep up to 4.4.0. This impacts the function deepExtend of the file libs/deep/src/deepExtend.ts. The manipulation leads to improperly controlled modification of object prototype at…
- CVE-2026-78181HIGHCVSS 7.3EG 7.32026-08-24
A weakness has been identified in ractivejs ractive up to 1.4.4. Impacted is the function Ractive#set of the component Keypath Handler. Executing a manipulation can lead to improperly controlled modification of object prototype attributes.…
- CVE-2026-78180HIGHCVSS 7.3EG 7.32026-08-24
A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider.getContextProps of the file components/dialog/index.tsx of the component deepMerge. Performing a manipulation of the a…
- CVE-2026-78178HIGHCVSS 7.3EG 7.32026-08-24
A vulnerability was determined in jQWidgets up to 24.0.1. This affects the function JQXLite.extend/jqxBaseFramework.extend of the file jqwidgets/jqx-all.js. This manipulation causes improperly controlled modification of object prototype at…
- CVE-2026-54737HIGHCVSS 7.3EG 7.32026-07-31
@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to 2.0.5, defaultsDeep() recursively merges user-supplied objects without filtering proto, constructor, and prototype, all…
- CVE-2026-14893HIGHCVSS 7.3EG 7.32026-07-28
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through its configuration normalization API.
- CVE-2026-6621HIGHCVSS 7.3EG 7.32026-04-20
A vulnerability was determined in 1024bit extend-deep up to 0.1.6. The impacted element is an unknown function of the file index.js. This manipulation of the argument __proto__ causes improperly controlled modification of object prototype …
- CVE-2026-6594HIGHCVSS 7.3EG 7.32026-04-20
A vulnerability was determined in brikcss merge up to 1.3.0. This affects an unknown part. Executing a manipulation of the argument __proto__/constructor.prototype/prototype can lead to improperly controlled modification of object prototyp…
Map vulnerabilities like CWE-1321 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1321 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →