← Back
CWE-1321

536 CVEs • Abstraction: Variant

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

JSON object

Loading...

CVEs (536)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tree Kit Project
1Tree Kit
Jul 9, 2026
Aug 16, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A Prototype Pollution issue in Cronvel Tree-kit v.0.7.4 and before allows a remote attacker to execute arbitrary code via the extend function.
1Hello.js Project
1Hello.js
Jun 17, 2026
Aug 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Prototype pollution vulnerability in MrSwitch hello.js version 1.18.6, allows remote attackers to execute arbitrary code via hello.utils.extend function.
1Underscore Keypath Project
1Underscore Keypath
Jun 17, 2026
Aug 1, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Versions of the package underscore-keypath from 0.0.11 are vulnerable to Prototype Pollution via the name argument of the setProperty() function. Exploiting this vulnerability is possible due to improper input sanitizati...Show more
Versions of the package underscore-keypath from 0.0.11 are vulnerable to Prototype Pollution via the name argument of the setProperty() function. Exploiting this vulnerability is possible due to improper input sanitization which allows the usage of arguments like “__proto__”.Show less
1Mongoosejs
1Mongoose
Jun 17, 2026
Jul 17, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Prototype Pollution in GitHub repository automattic/mongoose prior to 7.3.4.
1Protobufjs Project
1Protobufjs
Jun 17, 2026
Jul 5, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
"protobuf.js (aka protobufjs) 6.10.0 through 7.x before 7.2.5 allows Prototype Pollution, a different vulnerability than CVE-2022-25878. A user-controlled protobuf message can be used by an attacker to pollute the protot...Show more
"protobuf.js (aka protobufjs) 6.10.0 through 7.x before 7.2.5 allows Prototype Pollution, a different vulnerability than CVE-2022-25878. A user-controlled protobuf message can be used by an attacker to pollute the prototype of Object.prototype by adding and overwriting its data and functions. Exploitation can involve: (1) using the function parse to parse protobuf messages on the fly, (2) loading .proto files by using load/loadSync functions, or (3) providing untrusted input to the functions ReflectionObject.setParsedOption and util.setProperty.Show less
1Salesforce
1Tough Cookie
Jun 17, 2026
Jul 1, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in wh...Show more
Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized.Show less
1Flatnest Project
1Flatnest
Jun 17, 2026
Jun 30, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
All versions of the package flatnest are vulnerable to Prototype Pollution via the nest() function in the flatnest/nest.js file.
1Parseplatform
1Parse Server
Jun 17, 2026
Jun 28, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 5.5.2 and 6.2.1, an attacker can use a prototype pollution sink to trigger a remote code execution...Show more
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 5.5.2 and 6.2.1, an attacker can use a prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser. A patch is available in versions 5.5.2 and 6.2.1.Show less
1Progressbar.js Project
1Progressbar.js
Jun 17, 2026
Jun 12, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
All versions of the package progressbar.js are vulnerable to Prototype Pollution via the function extend() in the file utils.js.
1Dottie Project
1Dottie
Jun 17, 2026
Jun 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Versions of the package dottie before 2.0.4 are vulnerable to Prototype Pollution due to insufficient checks, via the set() function and the current variable in the /dottie.js file.
1Antfu
1Utils
Jun 17, 2026
May 30, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Prototype Pollution in GitHub repository antfu/utils prior to 0.7.3.
1Aiven
1Aiven
Jun 17, 2026
May 12, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
aiven-extras is a PostgreSQL extension. Versions prior to 1.1.9 contain a privilege escalation vulnerability, allowing elevation to superuser inside PostgreSQL databases that use the aiven-extras package. The vulnerabili...Show more
aiven-extras is a PostgreSQL extension. Versions prior to 1.1.9 contain a privilege escalation vulnerability, allowing elevation to superuser inside PostgreSQL databases that use the aiven-extras package. The vulnerability leverages missing schema qualifiers on privileged functions called by the aiven-extras extension. A low privileged user can create objects that collide with existing function names, which will then be executed instead. Exploiting this vulnerability could allow a low privileged user to acquire `superuser` privileges, which would allow full, unrestricted access to all data and database functions. And could lead to arbitrary code execution or data access on the underlying host as the `postgres` user. The issue has been patched as of version 1.1.9.Show less
1Strikingly
1Strikingly
Jun 17, 2026
May 8, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A prototype pollution vulnerability exists in Strikingly CMS which can result in reflected cross-site scripting (XSS) in affected applications and sites built with Strikingly. The vulnerability exists because of Striking...Show more
A prototype pollution vulnerability exists in Strikingly CMS which can result in reflected cross-site scripting (XSS) in affected applications and sites built with Strikingly. The vulnerability exists because of Strikingly JavaScript library parsing the URL fragment allows access to the __proto__ or constructor properties and the Object prototype. By leveraging an embedded gadget like jQuery, an attacker who convinces a victim to visit a specially crafted link could achieve arbitrary javascript execution in the context of the user's browser.Show less
1Aedart
1Ion
Jun 17, 2026
Apr 28, 2023
N/A· v4
3.7 LOW· v3
N/A· v2
@aedart/support is the support package for Ion, a monorepo for JavaScript/TypeScript packages. Prior to version `0.6.1`, there is a possible prototype pollution issue for the `MetadataRecord`, when merged with a base cla...Show more
@aedart/support is the support package for Ion, a monorepo for JavaScript/TypeScript packages. Prior to version `0.6.1`, there is a possible prototype pollution issue for the `MetadataRecord`, when merged with a base class' metadata object, in `meta` decorator from the `@aedart/support` package. The likelihood of exploitation is questionable, given that a class's metadata can only be set or altered when the class is decorated via `meta()`. Furthermore, object(s) of sensitive nature would have to be stored as metadata, before this can lead to a security impact. The issue has been patched in version `0.6.1`. Show less
1Tencent
1Vconsole
Jun 17, 2026
Apr 26, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
vConsole v3.15.0 was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions in core.ts.
1Sheetjs
1Sheetjs
Jun 17, 2026
Apr 24, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
SheetJS Community Edition before 0.19.3 allows Prototype Pollution via a crafted file. In other words. 0.19.2 and earlier are affected, whereas 0.19.3 and later are unaffected.
1Safe Eval Project
1Safe Eval
Jun 17, 2026
Apr 11, 2023
N/A· v4
10.0 CRITICAL· v3
N/A· v2
All versions of the package safe-eval are vulnerable to Sandbox Bypass due to improper input sanitization. The vulnerability is derived from prototype pollution exploitation. Exploiting this vulnerability might result in...Show more
All versions of the package safe-eval are vulnerable to Sandbox Bypass due to improper input sanitization. The vulnerability is derived from prototype pollution exploitation. Exploiting this vulnerability might result in remote code execution ("RCE"). **Vulnerable functions:** __defineGetter__, stack(), toLocaleString(), propertyIsEnumerable.call(), valueOf().Show less
1Safe Eval Project
1Safe Eval
Jun 17, 2026
Apr 11, 2023
N/A· v4
10.0 CRITICAL· v3
N/A· v2
All versions of the package safe-eval are vulnerable to Prototype Pollution via the safeEval function, due to improper sanitization of its parameter content.
1Xml2js Project
1Xml2js
Jun 17, 2026
Apr 5, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
xml2js version 0.4.23 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the __proto__ property t...Show more
xml2js version 0.4.23 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the __proto__ property to be edited.Show less
1Matrix
1Javascript Sdk
Jun 17, 2026
Mar 28, 2023
N/A· v4
8.2 HIGH· v3
N/A· v2
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 24.0.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioni...Show more
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 24.0.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the matrix-js-sdk can appear to be operating normally but be excluding or corrupting runtime data presented to the consumer. This vulnerability is distinct from GHSA-rfv9-x7hh-xc32 which covers a similar issue. The issue has been patched in matrix-js-sdk 24.0.0 and users are advised to upgrade. There are no known workarounds for this vulnerability.Show less