VulnSea

CWE-1321

CVEs classified under CWE-1321, newest first.

90 CVEsRSS

CVE-2026-48819Medium· 4.8
2mo ago

@hey-api/openapi-ts's `buildClientParams` template: prototype chain substitution via unknown `$<slot>___proto__` key

@hey-api/openapi-ts's `buildClientParams` template: prototype chain substitution via unknown `$<slot>___proto__` key

▾ Sunlithey-api · @hey-api/openapi-tsEPSS 0.35%via GHSA
CVE-2026-48795High· 8.6
2mo ago

@adonisjs/bodyparser has an incomplete fix for CVE-2026-25754

@adonisjs/bodyparser has an incomplete fix for CVE-2026-25754

▾ Twilightadonisjs · @adonisjs/bodyparserEPSS 0.55%via GHSA
CVE-2026-49252Critical· 9.9
3mo ago

deepstream is vulnerable to prototype pollution

deepstream is vulnerable to prototype pollution

▾ Midnightdeepstream · @deepstream/serverEPSS 0.47%via GHSA
CVE-2026-48714Critical· 9.1
3mo ago

i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting names

i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting names

▾ Midnighti18next-http-middleware · i18next-http-middlewareEPSS 0.66%via GHSA
CVE-2026-48713Critical· 9.1
3mo ago

i18next-fs-backend vulnerable to prototype pollution via crafted missing-key string

i18next-fs-backend vulnerable to prototype pollution via crafted missing-key string

▾ Midnighti18next-fs-backend · i18next-fs-backendEPSS 0.66%via GHSA
CVE-2026-55886Medium
3mo ago

jodit: Prototype pollution in Jodit via Jodit.modules.Helpers.set()

jodit: Prototype pollution in Jodit via Jodit.modules.Helpers.set()

▾ Sunlitjodit · joditEPSS 0.53%via GHSA
CVE-2026-55388High· 8.1
3mo ago

piscina: Prototype Pollution Gadget → RCE via inherited options.filename

piscina: Prototype Pollution Gadget → RCE via inherited options.filename

▾ Twilightpiscina · piscinaEPSS 0.45%via GHSA
CVE-2026-54306Medium· 5.4
3mo ago

n8n: Prototype Pollution enables confused-deputy execution via public webhooks

n8n: Prototype Pollution enables confused-deputy execution via public webhooks

▾ Sunlitn8n · n8nEPSS 0.28%via GHSA
CVE-2026-54312High· 8.5
3mo ago

n8n: Microsoft SQL Node Prototype Pollution

n8n: Microsoft SQL Node Prototype Pollution

▾ Twilightn8n · n8nEPSS 0.40%via GHSA
CVE-2026-49459Medium· 6.1
3mo ago

DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM

DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM

▾ Sunlitdompurify · dompurifyEPSS 0.36%via GHSA
CVE-2026-44495High· 7.0PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process h…

▾ Midnightaxios · axiosEPSS 1.0%via NVD
CVE-2026-44494High· 8.7PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's depen…

▾ Midnightaxios · axiosEPSS 0.93%via NVD
CVE-2026-46625High· 7.5PoC
3mo ago

JavaScript Cookie is a JavaScript API for handling cookies, client-side

JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, t…

▾ Midnightjs-cookie · javascript_cookieEPSS 0.99%via NVD
CVE-2026-45302High· 8.2
3mo ago

parse-nested-form-data is a tiny node module for parsing FormData by name into objects and arrays

parse-nested-form-data is a tiny node module for parsing FormData by name into objects and arrays. Prior to version 1.0.1, parseFormData() walks bracket and dot-notation FormData field names into nested objects without filtering reserved…

▾ TwilightEPSS 0.56%via NVD
CVE-2026-9101Medium· 4.3
4mo ago

Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering shell.openExternal after specific user behavior leading to "1-click" command execution.

Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering shell.openExternal after specific user behavior leading to "1-click" command execution.

▾ Sunlitmongodb · compassEPSS 0.45%via NVD
CVE-2026-44005Critical· 10.0
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes into the underlying host objects with otherReflectSet() an…

▾ Midnightvm2_project · vm2EPSS 0.83%via NVD
CVE-2026-42264High· 7.4PoC
4mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via d…

▾ Midnightaxios · axiosEPSS 0.97%via NVD
CVE-2026-42044Medium· 6.5PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's depend…

▾ Twilightaxios · axiosEPSS 0.86%via NVD
CVE-2026-42041Medium· 4.8PoC⚖ disputed
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution to silently suppress all HT…

▾ Twilightaxios · axiosEPSS 0.81%via NVD
CVE-2026-42033High· 7.4PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) sil…

▾ Midnightaxios · axiosEPSS 0.92%via NVD
CVE-2026-40190Medium· 5.6
5mo ago

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScript/TypeScript SDK (langsmith) contains an incomplete prototype pollution fix in its internally vendored lodash set() …

▾ Sunlitlangchain · langsmithEPSS 0.39%via NVD
CVE-2026-35209High· 7.5
5mo ago

defu is software that allows uers to assign default properties recursively

defu is software that allows uers to assign default properties recursively. Prior to version 6.1.5, applications that pass unsanitized user input (e.g. parsed JSON request bodies, database records, or config files from untrusted sources)…

▾ Twilightunjs · defuEPSS 0.52%via NVD
CVE-2026-34221Critical· 9.1
6mo ago

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, a prototype pollution vulnerability exists in the Utils.merge helper used internally by MikroORM w…

▾ Midnightmikro-orm · mikroormEPSS 0.51%via NVD
CVE-2026-33228Critical· 9.8
6mo ago

flatted is a circular JSON parser

flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the int…

▾ MidnightEPSS 0.99%via NVD
CVE-2026-29063Critical· 9.8
6mo ago

Immutable.js provides many Persistent Immutable data structures

Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. …

▾ Midnightimmutable-js · immutableEPSS 1.2%via NVD
CVE-2026-25521High· 8.8
7mo ago

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to before 2.0.39, a prototype pollution vulnerability exists in locutus. Despite a previous fix that attempted to mitig…

▾ Twilightlocutus · locutusEPSS 0.44%via NVD
CVE-2025-61140Critical· 9.8
8mo ago

The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.

The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.

▾ Midnightdchester · jsonpathEPSS 0.51%via NVD
CVE-2025-13465Medium· 5.3PoC
8mo ago

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion …

▾ Twilightlodash · lodashEPSS 1.8%via NVD
CVE-2024-21529High· 8.2
2y ago

Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user input sanitization

Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user input sanitization. This vulnerability allows the attacker to inject malicious object property using the built-in Obj…

▾ TwilightEPSS 0.75%via NVD
CVE-2021-28860Critical· 9.1
5y ago

In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions

In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This wil…

▾ Midnightadaltas · mixmeEPSS 1.8%via NVD
CWE-1321 vulnerabilities (CVEs) — page 3 · VulnSea