---
id: CVE-2026-106550
title: >-
  Mozilla's Node-convict (version 6.2.2 and later) is vulnerable to a Denial of
  Service vulnerability caused by incomplete prototype‑pollution protections in
  config.set()
summary: >-
  Mozilla's Node-convict (version 6.2.2 and later) is vulnerable to a Denial of
  Service vulnerability caused by incomplete prototype‑pollution protections in
  config.set(). An attacker controlling the configuration key can write
  arbitrary p…
severity: none
cwe:
  - CWE-1321
  - CWE-915
  - CWE-400
vendor: Mozilla
product: Node-convict
affected:
  - Node-convict 6.2.2
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T21:17:18.810'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-106550'
references:
  - url: 'https://github.com/mozilla/node-convict'
    label: cret@cert.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T21:20:28.986Z'
---

## Overview

Mozilla's Node-convict (version 6.2.2 and later) is vulnerable to a Denial of Service vulnerability caused by incomplete prototype‑pollution protections in config.set(). An attacker controlling the configuration key can write arbitrary properties to constructor.<key>, which walk() resolves to the global Object function. This allows overwriting core JavaScript methods such as Object.assign, leading to persistent process-wide failures and requiring a restart. The issue bypasses existing filters that only block constructor.prototype.* and __proto__.*. Exploitation requires an endpoint that forwards attacker-controlled keys into config.set().

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
