CWE-1321— Improperly Controlled Modification of Object Prototype Attributes (Prototype Pollution)
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.— MITRE CWE catalog
622 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1321page 9 of 13
- CVE-2025-13204HIGHCVSS 7.3EG 7.32025-11-14
npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolv…
- CVE-2025-55195HIGHCVSS 7.3EG 7.32025-08-14
@std/toml is the Deno Standard Library. Prior to version 1.0.9, an attacker can pollute the prototype chain in Node.js runtime and Browser when parsing untrusted TOML data, thus achieving Prototype Pollution (PP) vulnerability. This is bec…
- CVE-2025-3197HIGHCVSS 7.3EG 7.32025-04-04
Versions of the package expand-object from 0.0.0 are vulnerable to Prototype Pollution in the expand() function in index.js. This function expands the given string into an object and allows a nested property to be set without checking the …
- CVE-2024-45801HIGHCVSS 7.3EG 7.32024-09-16
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that malicious HTML using special nesting techniques can bypass the depth checking added to DOMPurify in recent releases. It …
- CVE-2024-39003HIGHCVSS 7.3EG 7.32024-07-01
amoyjs amoy common v1.0.10 was discovered to contain a prototype pollution via the function setValue. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
- CVE-2024-38994HIGHCVSS 7.3EG 7.32024-07-01
amoyjs amoy common v1.0.10 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
- CVE-2023-26135HIGHCVSS 7.3EG 7.32023-06-30
All versions of the package flatnest are vulnerable to Prototype Pollution via the nest() function in the flatnest/nest.js file.
- CVE-2022-21169HIGHCVSS 7.3EG 7.32022-09-26
The package express-xss-sanitizer before 1.1.3 are vulnerable to Prototype Pollution via the allowedTags attribute, allowing the attacker to bypass xss sanitization.
- CVE-2020-28471HIGHCVSS 7.3EG 7.32022-07-25
This affects the package properties-reader before 2.2.0.
- CVE-2020-28461HIGHCVSS 7.3EG 7.32022-07-25
This affects the package js-ini before 1.3.0. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can be exploited further depending on the cont…
- CVE-2020-28441HIGHCVSS 7.3EG 7.32022-07-25
This affects the package conf-cfg-ini before 1.2.2. If an attacker submits a malicious INI file to an application that parses it with decode, they will pollute the prototype on the application. This can be exploited further depending on th…
- CVE-2022-21189HIGHCVSS 7.3EG 7.32022-05-01
The package dexie before 3.2.2, from 4.0.0-alpha.1 and before 4.0.0-alpha.3 are vulnerable to Prototype Pollution in the Dexie.setByKeyPath(obj, keyPath, value) function which does not properly check the keys being set (like __proto__ or c…
- CVE-2022-21803HIGHCVSS 7.3EG 7.32022-04-12
This affects the package nconf before 0.11.4. When using the memory engine, it is possible to store a nested JSON representation of the configuration. The .set() function, that is responsible for setting the configuration properties, is vu…
- CVE-2021-23682HIGHCVSS 7.3EG 7.32022-02-16
This affects the package litespeed.js before 0.3.12; the package appwrite/server-ce from 0.12.0 and before 0.12.2, before 0.11.1. When parsing the query string in the getJsonFromUrl function, the key that is set in the result object is not…
- CVE-2021-23558HIGHCVSS 7.3EG 7.32022-01-28
The package bmoor before 0.10.1 are vulnerable to Prototype Pollution due to missing sanitization in set function. **Note:** This vulnerability derives from an incomplete fix in [CVE-2020-7736](https://security.snyk.io/vuln/SNYK-JS-BMOOR-5…
- CVE-2021-23518HIGHCVSS 7.3EG 7.32022-01-21
The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype pro…
- CVE-2021-23568HIGHCVSS 7.3EG 7.32022-01-10
The package extend2 before 1.0.1 are vulnerable to Prototype Pollution via the extend function due to unsafe recursive merge.
- CVE-2021-23419HIGHCVSS 7.3EG 7.32021-08-08
This affects the package open-graph before 0.2.6. The function parse could be tricked into adding or modifying properties of Object.prototype using a __proto__ or constructor payload.
- CVE-2021-23403HIGHCVSS 7.3EG 7.32021-07-02
All versions of package ts-nodash are vulnerable to Prototype Pollution via the Merge() function due to lack of validation input.
- CVE-2021-23402HIGHCVSS 7.3EG 7.32021-07-02
All versions of package record-like-deep-assign are vulnerable to Prototype Pollution via the main functionality.
- CVE-2021-23395HIGHCVSS 7.3EG 7.32021-06-15
This affects all versions of package nedb. The library could be tricked into adding or modifying properties of Object.prototype using a __proto__ or constructor.prototype payload.
- CVE-2020-28458HIGHCVSS 7.3EG 7.32020-12-16
All versions of package datatables.net are vulnerable to Prototype Pollution due to an incomplete fix for https://snyk.io/vuln/SNYK-JS-DATATABLESNET-598806.
- CVE-2020-7766HIGHCVSS 7.3EG 7.32020-11-10
This affects all versions of package json-ptr. The issue occurs in the set operation (https://flitbit.github.io/json-ptr/classes/_src_pointer_.jsonpointer.htmlset) when the force flag is set to true. The function recursively set the proper…
- CVE-2020-7743HIGHCVSS 7.3EG 7.32020-10-13
The package mathjs before 7.5.1 are vulnerable to Prototype Pollution via the deepExtend function that runs upon configuration updates.
- CVE-2020-7737HIGHCVSS 7.3EG 7.32020-10-02
All versions of package safetydance are vulnerable to Prototype Pollution via the set function.
- CVE-2020-7736HIGHCVSS 7.3EG 7.32020-10-02
The package bmoor before 0.8.12 are vulnerable to Prototype Pollution via the set function.
- CVE-2020-7679HIGHCVSS 7.3EG 7.32020-06-19
In all versions of package casperjs, the mergeObjects utility function is susceptible to Prototype Pollution.
- CVE-2020-8116HIGHCVSS 7.3EG 7.32020-02-04
Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbitrary properties to JavaScript language constructs such as objects.
- CVE-2026-53676HIGHCVSS 7.2EG 7.22026-06-17
ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandboxed context by a user who can log in to the affected product with the tenant administrator privilege (TENANT_ADMIN).
- CVE-2026-46681HIGHCVSS 7.2EG 7.22026-05-21
@nevware21/ts-utils is a comprehensive TypeScript/JavaScript utility library. Prior to version 0.14.0, the _copyProps function in lib/src/object/copy.ts uses for...in to iterate over source object properties without an Object.hasOwnPropert…
- CVE-2026-25754HIGHCVSS 7.2EG 7.22026-02-06
AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a prototype pollution vulnerability in AdonisJS multipart form-data parsing may allow a remote attacker to manipulate object prototypes at runtime. T…
- CVE-2024-33519HIGHCVSS 7.2EG 7.22024-07-24
A vulnerability in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN gateway could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vuln…
- CVE-2024-22443HIGHCVSS 7.2EG 7.22024-07-24
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could …
- CVE-2022-3901HIGHCVSS 7.2EG 7.22023-02-20
Prototype Pollution in Visioweb.js 1.10.6 allows attackers to execute XSS on the client system.
- CVE-2022-41878HIGHCVSS 7.2EG 7.22022-11-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 5.3.2 or 4.10.19, keywords that are specified in the Parse Server option `requestKeywordDenylist` can be injected …
- CVE-2022-41879HIGHCVSS 7.2EG 7.22022-11-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 5.3.3 or 4.10.20, a compromised Parse Server Cloud Code Webhook target endpoint allows an attacker to use prototyp…
- CVE-2021-21304HIGHCVSS 7.2EG 7.22021-02-08
Dynamoose is an open-source modeling tool for Amazon's DynamoDB. In Dynamoose from version 2.0.0 and before version 2.7.0 there was a prototype pollution vulnerability in the internal utility method "lib/utils/object/set.ts". This method i…
- CVE-2019-17317HIGHCVSS 7.2EG 7.22019-10-07
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the UpgradeWizard module by an Admin user.
- CVE-2019-17315HIGHCVSS 7.2EG 7.22019-10-07
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Administration module by an Admin user.
- CVE-2019-9058HIGHCVSS 7.2EG 7.22019-03-26
An issue was discovered in CMS Made Simple 2.2.8. In the administrator page admin/changegroupperm.php, it is possible to send a crafted value in the sel_groups parameter that leads to authenticated object injection.
- CVE-2018-19274HIGHCVSS 7.2EG 7.22018-11-17
Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Phar deserialization when an attacker has access to the Admin Control Panel with founder permissions.
- CVE-2018-6195HIGHCVSS 7.2EG 7.22018-01-30
admin/partials/wp-splashing-admin-main.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPress allows authenticated (administrator, editor, or author) remote attackers to conduct PHP Object Injection attacks via…
- CVE-2026-89011HIGHCVSS 7.1EG 7.12026-09-10
isomorphic-git before 1.42.0 contains a prototype pollution vulnerability in the getRemoteInfo function that allows a malicious Git server operator to pollute Object.prototype by advertising crafted ref names containing '__proto__' path se…
- CVE-2026-71553HIGHCVSS 7.1EG 7.12026-08-17
ApostropheCMS is an open-source Node.js content management system. In 4.32.0 and earlier, PATCH /api/v1/article/:id accepts the inherited path toString.call and passes it through the utility module to apos.util.set() and apos.util.get(), a…
- CVE-2026-59206HIGHCVSS 7.1EG 7.12026-07-09
n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated user with the default workflow:create permission could pollute Object.prototype through a crafted workflow saved, updated, or impo…
- CVE-2023-6293HIGHCVSS 7.1EG 7.12023-11-24
Prototype Pollution in GitHub repository robinbuschmann/sequelize-typescript prior to 2.1.6.
- CVE-2022-46175HIGHCVSS 7.1EG 7.12022-12-24
JSON5 is an extension to the popular JSON file format that aims to be easier to write and maintain by hand (e.g. for config files). The `parse` method of the JSON5 library before and including versions 1.0.1 and 2.2.1 does not restrict par…
- CVE-2025-34146HIGHCVSS 7.0EG 7.02025-07-31
A prototype pollution vulnerability exists in @nyariv/sandboxjs versions <= 0.8.23, allowing attackers to inject arbitrary properties into Object.prototype via crafted JavaScript code. This can result in a denial-of-service (DoS) condition…
- CVE-2026-101908MEDIUMCVSS 6.9EG 6.92026-09-28
Axios is a promise-based HTTP client for the browser and Node.js. From 1.7.0 until 1.20.0, the fetch adapter constructs a Request with sanitized resolvedOptions but then calls fetch with the original fetchOptions. A separate same-process p…
- CVE-2026-101904MEDIUMCVSS 6.9EG 6.92026-09-28
Axios is a promise-based HTTP client for the browser and Node.js. From 1.0.0 until 1.20.0, the dispatchRequest function normalizes inherited Object.prototype.headers from a replacement request configuration. A separate same-process prototy…
Map vulnerabilities like CWE-1321 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1321 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →