← Back
CWE-1321

536 CVEs • Abstraction: Variant

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

JSON object

Loading...

CVEs (536)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Jul 1, 2024
N/A· v4
10.0 CRITICAL· v3
N/A· v2
jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injec...Show more
jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.Show less
1Swiperjs
1Swiper
Jun 17, 2026
Jul 1, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
adolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function extendDefaults. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via inject...Show more
adolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function extendDefaults. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.Show less
1Ag Grid
1Ag Grid
Jun 17, 2026
Jul 1, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
ag-grid-community v31.3.2 and ag-grid-enterprise v31.3.2 were discovered to contain a prototype pollution via the _.mergeDeep function. This vulnerability allows attackers to execute arbitrary code or cause a Denial of S...Show more
ag-grid-community v31.3.2 and ag-grid-enterprise v31.3.2 were discovered to contain a prototype pollution via the _.mergeDeep function. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.Show less
1Amoyjs
1Common
Jun 17, 2026
Jul 1, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
amoyjs amoy common v1.0.10 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary...Show more
amoyjs amoy common v1.0.10 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.Show less
-
-
Jun 17, 2026
Jul 1, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
airvertco frappejs v0.0.11 was discovered to contain a prototype pollution via the function registerView. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arb...Show more
airvertco frappejs v0.0.11 was discovered to contain a prototype pollution via the function registerView. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.Show less
-
-
Jun 17, 2026
Jul 1, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
akbr patch-into v1.0.1 was discovered to contain a prototype pollution via the function patchInto. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary...Show more
akbr patch-into v1.0.1 was discovered to contain a prototype pollution via the function patchInto. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.Show less
-
-
Jun 17, 2026
Jul 1, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
aofl cli-lib v3.14.0 was discovered to contain a prototype pollution via the component defaultsDeep. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrar...Show more
aofl cli-lib v3.14.0 was discovered to contain a prototype pollution via the component defaultsDeep. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.Show less
-
-
Jun 17, 2026
Jun 17, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
akbr update 1.0.0 is vulnerable to Prototype Pollution via update/index.js.
-
-
Jun 17, 2026
Jun 17, 2024
N/A· v4
8.3 HIGH· v3
N/A· v2
apphp js-object-resolver < 3.1.1 is vulnerable to Prototype Pollution via Module.setNestedProperty.
-
-
Jun 17, 2026
Jun 17, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
A Prototype Pollution issue in flatten-json 1.0.1 allows an attacker to execute arbitrary code via module.exports.unflattenJSON (flatten-json/index.js:42)
-
-
Jun 17, 2026
Jun 17, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
almela obx before v.0.0.4 has a Prototype Pollution issue which allows arbitrary code execution via the obx/build/index.js:656), reduce (@almela/obx/build/index.js:470), Object.set (obx/build/index.js:269) component.
-
-
Jun 17, 2026
Jun 17, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
alexbinary object-deep-assign 1.0.11 is vulnerable to Prototype Pollution via the extend() method of Module.deepAssign (/src/index.js)
-
-
Jun 17, 2026
Jun 17, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
A Prototype Pollution issue in byondreal accessor <= 1.0.0 allows an attacker to execute arbitrary code via @byondreal/accessor/index.
-
-
Jun 17, 2026
Jun 17, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A Prototype Pollution issue in cdr0 sg 1.0.10 allows an attacker to execute arbitrary code.
-
-
Jun 17, 2026
May 29, 2024
N/A· v4
8.2 HIGH· v3
N/A· v2
Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitization passed to fields and tables when using nestTables.
-
-
Jun 17, 2026
May 20, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
A Prototype Pollution issue in API Dev Tools json-schema-ref-parser v.11.0.0 and v.11.1.0 allows a remote attacker to execute arbitrary code via the bundle()`, `parse()`, `resolve()`, `dereference() functions.
-
-
Jun 17, 2026
May 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
A Prototype Pollution issue in MiguelCastillo @bit/loader v.10.0.3 allows an attacker to execute arbitrary code via the M function e argument in index.js.
-
-
Jun 17, 2026
May 16, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
njwt up to v0.4.0 was discovered to contain a prototype pollution in the Parser.prototype.parse method.
1Freescout
1Freescout
Jun 17, 2026
May 14, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
FreeScout is a free, self-hosted help desk and shared mailbox. Versions of FreeScout prior to 1.8.139 contain a Prototype Pollution vulnerability in the `/public/js/main.js` source file. The Prototype Pollution arises be...Show more
FreeScout is a free, self-hosted help desk and shared mailbox. Versions of FreeScout prior to 1.8.139 contain a Prototype Pollution vulnerability in the `/public/js/main.js` source file. The Prototype Pollution arises because the `getQueryParam` Function recursively merges an object containing user-controllable properties into an existing object (For URL Query Parameters Parsing), without first sanitizing the keys. This can allow an attacker to inject a property with a key `__proto__`, along with arbitrarily nested properties. The merge operation assigns the nested properties to the `params` object's prototype instead of the target object itself. As a result, the attacker can pollute the prototype with properties containing harmful values, which are then inherited by user-defined objects and subsequently used by the application dangerously. The vulnerability lets an attacker control properties of objects that would otherwise be inaccessible. If the application subsequently handles an attacker-controlled property in an unsafe way, this can potentially be chained with other vulnerabilities like DOM-based XSS, Open Redirection, Cookie Manipulation, Link Manipulation, HTML Injection, etc. Version 1.8.139 contains a patch for the issue.Show less
1Jenkins
1Subversion Partial Release Manager
Jun 17, 2026
May 2, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically disables the fix for CVE-2016-3721 whenever a build is triggered from a release tag, by setting the Java system property 'hudson.model....Show more
Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically disables the fix for CVE-2016-3721 whenever a build is triggered from a release tag, by setting the Java system property 'hudson.model.ParametersAction.keepUndefinedParameters'.Show less