CWE-1321
536 CVEs • Abstraction: Variant
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
CVEs (536)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability classified as critical has been found in Furqan node-whois. Affected is an unknown function of the file index.coffee. The manipulation leads to improperly controlled modification of object prototype attri...Show more |
A vulnerability classified as problematic has been found in chbrown rfc6902. This affects an unknown part of the file pointer.ts. The manipulation leads to improperly controlled modification of object prototype attribute...Show more |
3Debian OpenjsfQs Project3Debian Linux ExpressQsJun 17, 2026 Nov 26, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an...Show more |
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 5.3.2 or 4.10.19, keywords that are specified in the Parse Server option `requestKeywordDenylis...Show more |
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 5.3.3 or 4.10.20, a compromised Parse Server Cloud Code Webhook target endpoint allows an attac...Show more |
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 4.10.18, and prior to 5.3.1 on the 5.X branch, are vulnerable to Remote Code Execution via prototy...Show more |
1Deep Parse Json Project 1Deep Parse Json Jun 17, 2026 Nov 3, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 deep-parse-json version 1.0.2 allows an external attacker to edit or add new properties to an object. This is possible because the application does not correctly validate the incoming JSON keys, thus allowing the '__prot...Show more |
1Fastest Json Copy Project 1Fastest Json Copy Jun 17, 2026 Nov 3, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 fastest-json-copy version 1.0.1 allows an external attacker to edit or add new properties to an object. This is possible because the application does not correctly validate the incoming JSON keys, thus allowing the '__pr...Show more |
1Deep Object Diff Project 1Deep Object Diff Jun 17, 2026 Nov 3, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 deep-object-diff version 1.1.0 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the '__proto__'...Show more |
1Browserify Shim Project 1Browserify Shim Jun 17, 2026 Oct 31, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the shimPath variable in resolve-shims.js. |
1Browserify Shim Project 1Browserify Shim Jun 17, 2026 Oct 28, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the fullPath variable in resolve-shims.js. |
Winter is a free, open-source content management system based on the Laravel PHP framework. The Snowboard framework in versions 1.1.8, 1.1.9, and 1.2.0 is vulnerable to prototype pollution in the main Snowboard class as...Show more |
Feather-Sequalize cleanQuery method uses insecure recursive logic to filter unsupported keys from the query object. This results in a Remote Code Execution (RCE) with privileges of application. |
Prototype pollution vulnerability in function DEFNODE in ast.js in mishoo UglifyJS 3.13.2 via the name variable in ast.js. NOTE: the vendor considers this an invalid report. |
1Grunt Karma Project 1Grunt Karma Jun 17, 2026 Oct 14, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Prototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key variable in grunt-karma.js. |
2Debian Webpack.js2Debian Linux Loader UtilsJun 17, 2026 Oct 12, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3. |
Prototype pollution vulnerability in function enable in mockery.js in mfncooper mockery commit 822f0566fd6d72af8c943ae5ca2aa92e516aa2cf via the key variable in mockery.js. |
Prototype pollution vulnerability in tschaub gh-pages 3.1.0 via the partial variable in util.js. |
1Browserify Shim Project 1Browserify Shim Jun 17, 2026 Oct 11, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the k variable in resolve-shims.js. |
1Js Beautify Project 1Js Beautify Jun 17, 2026 Oct 11, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Prototype pollution vulnerability in beautify-web js-beautify 1.13.7 via the name variable in options.js. |