CWE-1321
536 CVEs • Abstraction: Variant
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
CVEs (536)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Xmldom Project2Debian Linux XmldomJun 17, 2026 Oct 11, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of...Show more |
1Express Xss Sanitizer Project 1Express Xss Sanitizer Jun 17, 2026 Sep 26, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The package express-xss-sanitizer before 1.1.3 are vulnerable to Prototype Pollution via the allowedTags attribute, allowing the attacker to bypass xss sanitization. |
hoek before 8.5.1 and 9.x before 9.0.3 allows prototype poisoning in the clone function. |
Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js. |
Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the packageName variable in npm-convert.js. |
Prototype pollution vulnerability in stealjs steal 2.2.4 via the optionName variable in main.js. |
Prototype pollution vulnerability in function extend in babel.js in stealjs steal 2.2.4 via the key variable in babel.js. |
Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVersion variable in npm-convert.js. |
3Fedoraproject PostgresqlRedhat3Enterprise Linux FedoraPostgresqlJun 17, 2026 Aug 18, 2022 N/A· v4 8.0 HIGH· v3 N/A· v2 A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension...Show more |
1Typescript Deep Merge Project 1Typescript Deep Merge Jun 17, 2026 Aug 9, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The package ts-deepmerge before 2.0.2 are vulnerable to Prototype Pollution due to missing sanitization of the merge function. |
Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6. |
All versions of package @ianwalter/merge are vulnerable to Prototype Pollution via the main (merge) function. Maintainer suggests using @generates/merger instead. |
1Set Deep Prop Project 1Set Deep Prop Jun 17, 2026 Jul 25, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 All versions of package set-deep-prop are vulnerable to Prototype Pollution via the main functionality. |
1Properties Reader Project 1Properties Reader Jun 17, 2026 Jul 25, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 This affects the package properties-reader before 2.2.0. |
This affects all versions of package ion-parser. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can be exploited further...Show more |
This affects the package js-ini before 1.3.0. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can be exploited further de...Show more |
1Conf Cfg Ini Project 1Conf Cfg Ini Jun 17, 2026 Jul 25, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 This affects the package conf-cfg-ini before 1.2.2. If an attacker submits a malicious INI file to an application that parses it with decode, they will pollute the prototype on the application. This can be exploited furt...Show more |
1Grunt Util Property Project 1Grunt Util Property Jun 17, 2026 Jul 17, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 This affects all versions of package grunt-util-property. The function call could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload. |
1Deep.assign Project 1Deep.assign Jun 17, 2026 Jun 30, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 deep.assign npm package 0.0.0-alpha.0 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'). |
Underscore.deep is a collection of Underscore mixins that operate on nested objects. Versions of `underscore.deep` prior to version 0.5.3 are vulnerable to a prototype pollution vulnerability. An attacker can craft a mal...Show more |