CVE-2026-106448High· 8.9▾ TwilightStableLib is a stable library of useful TypeScript and JavaScript code. Prior to 2.0.4, the @stablelib/cbor CBOR map decoding path creates ordinary JavaScript objects and assigns attacker-controlled keys with bracket assignment. A map ke…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 49 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
StableLib is a stable library of useful TypeScript and JavaScript code. Prior to 2.0.4, the @stablelib/cbor CBOR map decoding path creates ordinary JavaScript objects and assigns attacker-controlled keys with bracket assignment. A map key named proto invokes the inherited prototype setter instead of creating an ordinary own property, allowing the decoded object's prototype to contain attacker-controlled authorization or feature-flag values. Downstream code that trusts normal property lookup or merges the decoded object can therefore make security-sensitive decisions using inherited attacker data. This issue is fixed in version 2.0.4.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-106447High· 8.7StableLib is a stable library of useful TypeScript and JavaScript code
CVE-2026-106550NoneMozilla's Node-convict (version 6.2.2 and later) is vulnerable to a Denial of Service vulnerability caused by incomplete prototype‑pollution protections in config.set()
CVE-2026-105857Critical· 10.0Payload is a free and open source headless content management system
CVE-2026-105858High· 8.1Payload is a free and open source headless content management system
CVE-2026-105844Critical· 9.3Payload is a free and open source headless content management system
CVE-2026-104852High· 8.2GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas