← Back
CWE-1321

536 CVEs • Abstraction: Variant

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

JSON object

Loading...

CVEs (536)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Xmldom Project
2Debian Linux
Xmldom
Jun 17, 2026
Oct 11, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of...Show more
A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however, some third parties takes the position that "A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted."Show less
1Express Xss Sanitizer Project
1Express Xss Sanitizer
Jun 17, 2026
Sep 26, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The package express-xss-sanitizer before 1.1.3 are vulnerable to Prototype Pollution via the allowedTags attribute, allowing the attacker to bypass xss sanitization.
1Hapijs
1Hoek
Jun 17, 2026
Sep 23, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
hoek before 8.5.1 and 9.x before 9.0.3 allows prototype poisoning in the clone function.
1Stealjs
1Steal
Jun 17, 2026
Sep 20, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js.
1Stealjs
1Steal
Jun 17, 2026
Sep 16, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the packageName variable in npm-convert.js.
1Stealjs
1Steal
Jun 17, 2026
Sep 15, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Prototype pollution vulnerability in stealjs steal 2.2.4 via the optionName variable in main.js.
1Stealjs
1Steal
Jun 17, 2026
Sep 15, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Prototype pollution vulnerability in function extend in babel.js in stealjs steal 2.2.4 via the key variable in babel.js.
1Stealjs
1Steal
Jul 9, 2026
Sep 15, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVersion variable in npm-convert.js.
3Fedoraproject
PostgresqlRedhat
3Enterprise Linux
FedoraPostgresql
Jun 17, 2026
Aug 18, 2022
N/A· v4
8.0 HIGH· v3
N/A· v2
A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension...Show more
A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and the ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS. Given all three prerequisites, this flaw allows an attacker to run arbitrary code as the victim role, which may be a superuser.Show less
1Typescript Deep Merge Project
1Typescript Deep Merge
Jun 17, 2026
Aug 9, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The package ts-deepmerge before 2.0.2 are vulnerable to Prototype Pollution due to missing sanitization of the merge function.
1Mongoosejs
1Mongoose
Jun 17, 2026
Jul 28, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6.
1Merge Project
1Merge
Jun 17, 2026
Jul 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
All versions of package @ianwalter/merge are vulnerable to Prototype Pollution via the main (merge) function. Maintainer suggests using @generates/merger instead.
1Set Deep Prop Project
1Set Deep Prop
Jun 17, 2026
Jul 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
All versions of package set-deep-prop are vulnerable to Prototype Pollution via the main functionality.
1Properties Reader Project
1Properties Reader
Jun 17, 2026
Jul 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This affects the package properties-reader before 2.2.0.
1Ion Parser Project
1Ion Parser
Jun 17, 2026
Jul 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This affects all versions of package ion-parser. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can be exploited further...Show more
This affects all versions of package ion-parser. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can be exploited further depending on the context.Show less
1Js Ini Project
1Js Ini
Jun 17, 2026
Jul 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This affects the package js-ini before 1.3.0. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can be exploited further de...Show more
This affects the package js-ini before 1.3.0. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can be exploited further depending on the context.Show less
1Conf Cfg Ini Project
1Conf Cfg Ini
Jun 17, 2026
Jul 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This affects the package conf-cfg-ini before 1.2.2. If an attacker submits a malicious INI file to an application that parses it with decode, they will pollute the prototype on the application. This can be exploited furt...Show more
This affects the package conf-cfg-ini before 1.2.2. If an attacker submits a malicious INI file to an application that parses it with decode, they will pollute the prototype on the application. This can be exploited further depending on the context.Show less
1Grunt Util Property Project
1Grunt Util Property
Jun 17, 2026
Jul 17, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
This affects all versions of package grunt-util-property. The function call could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
1Deep.assign Project
1Deep.assign
Jun 17, 2026
Jun 30, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
deep.assign npm package 0.0.0-alpha.0 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution').
1Clever
1Underscore.deep
Jun 17, 2026
Jun 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Underscore.deep is a collection of Underscore mixins that operate on nested objects. Versions of `underscore.deep` prior to version 0.5.3 are vulnerable to a prototype pollution vulnerability. An attacker can craft a mal...Show more
Underscore.deep is a collection of Underscore mixins that operate on nested objects. Versions of `underscore.deep` prior to version 0.5.3 are vulnerable to a prototype pollution vulnerability. An attacker can craft a malicious payload and pass it to `deepFromFlat`, which would pollute any future Objects created. Any users that have `deepFromFlat` or `deepPick` (due to its dependency on `deepFromFlat`) in their code should upgrade to version 0.5.3 as soon as possible. Users unable to upgrade may mitigate this issue by modifying `deepFromFlat` to prevent specific keywords which will prevent this from happening.Show less