CWE-1321
CVEs classified under CWE-1321, newest first.
90 CVEsRSS
CVE-2026-48819Medium· 4.8@hey-api/openapi-ts's `buildClientParams` template: prototype chain substitution via unknown `$<slot>___proto__` key
@hey-api/openapi-ts's `buildClientParams` template: prototype chain substitution via unknown `$<slot>___proto__` key
CVE-2026-48795High· 8.6@adonisjs/bodyparser has an incomplete fix for CVE-2026-25754
@adonisjs/bodyparser has an incomplete fix for CVE-2026-25754
CVE-2026-49252Critical· 9.9deepstream is vulnerable to prototype pollution
deepstream is vulnerable to prototype pollution
CVE-2026-48714Critical· 9.1i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting names
i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting names
CVE-2026-48713Critical· 9.1i18next-fs-backend vulnerable to prototype pollution via crafted missing-key string
i18next-fs-backend vulnerable to prototype pollution via crafted missing-key string
CVE-2026-55886Mediumjodit: Prototype pollution in Jodit via Jodit.modules.Helpers.set()
jodit: Prototype pollution in Jodit via Jodit.modules.Helpers.set()
CVE-2026-55388High· 8.1piscina: Prototype Pollution Gadget → RCE via inherited options.filename
piscina: Prototype Pollution Gadget → RCE via inherited options.filename
CVE-2026-54306Medium· 5.4n8n: Prototype Pollution enables confused-deputy execution via public webhooks
n8n: Prototype Pollution enables confused-deputy execution via public webhooks
CVE-2026-54312High· 8.5n8n: Microsoft SQL Node Prototype Pollution
n8n: Microsoft SQL Node Prototype Pollution
CVE-2026-49459Medium· 6.1DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM
DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM
CVE-2026-44495High· 7.0PoCAxios is a promise based HTTP client for the browser and Node.js
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process h…
CVE-2026-44494High· 8.7PoCAxios is a promise based HTTP client for the browser and Node.js
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's depen…
CVE-2026-46625High· 7.5PoCJavaScript Cookie is a JavaScript API for handling cookies, client-side
JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, t…
CVE-2026-45302High· 8.2parse-nested-form-data is a tiny node module for parsing FormData by name into objects and arrays
parse-nested-form-data is a tiny node module for parsing FormData by name into objects and arrays. Prior to version 1.0.1, parseFormData() walks bracket and dot-notation FormData field names into nested objects without filtering reserved…
CVE-2026-9101Medium· 4.3Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering shell.openExternal after specific user behavior leading to "1-click" command execution.
Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering shell.openExternal after specific user behavior leading to "1-click" command execution.
CVE-2026-44005Critical· 10.0vm2 is an open source vm/sandbox for Node.js
vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes into the underlying host objects with otherReflectSet() an…
CVE-2026-42264High· 7.4PoCAxios is a promise based HTTP client for the browser and Node.js
Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via d…
CVE-2026-42044Medium· 6.5PoCAxios is a promise based HTTP client for the browser and Node.js
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's depend…
CVE-2026-42041Medium· 4.8PoC⚖ disputedAxios is a promise based HTTP client for the browser and Node.js
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution to silently suppress all HT…
CVE-2026-42033High· 7.4PoCAxios is a promise based HTTP client for the browser and Node.js
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) sil…
CVE-2026-40190Medium· 5.6LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScript/TypeScript SDK (langsmith) contains an incomplete prototype pollution fix in its internally vendored lodash set() …
CVE-2026-35209High· 7.5defu is software that allows uers to assign default properties recursively
defu is software that allows uers to assign default properties recursively. Prior to version 6.1.5, applications that pass unsanitized user input (e.g. parsed JSON request bodies, database records, or config files from untrusted sources)…
CVE-2026-34221Critical· 9.1MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns
MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, a prototype pollution vulnerability exists in the Utils.merge helper used internally by MikroORM w…
CVE-2026-33228Critical· 9.8flatted is a circular JSON parser
flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the int…
CVE-2026-29063Critical· 9.8Immutable.js provides many Persistent Immutable data structures
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. …
CVE-2026-25521High· 8.8Locutus brings stdlibs of other programming languages to JavaScript for educational purposes
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to before 2.0.39, a prototype pollution vulnerability exists in locutus. Despite a previous fix that attempted to mitig…
CVE-2025-61140Critical· 9.8The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
CVE-2025-13465Medium· 5.3PoCLodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions
Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion …
CVE-2024-21529High· 8.2Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user input sanitization
Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user input sanitization. This vulnerability allows the attacker to inject malicious object property using the built-in Obj…
CVE-2021-28860Critical· 9.1In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions
In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This wil…