CWE-1321
536 CVEs • Abstraction: Variant
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
CVEs (536)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Libnested Project 1Libnested Jun 17, 2026 Mar 17, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The package libnested before 1.5.2 are vulnerable to Prototype Pollution via the set function in index.js. **Note:** This vulnerability derives from an incomplete fix for [CVE-2020-28283](https://security.snyk.io/vuln/SN...Show more |
The package bodymen from 0.0.0 are vulnerable to Prototype Pollution via the handler function which could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload. **Note:** This vulne...Show more |
SailsJS Sails.js <=1.4.0 is vulnerable to Prototype Pollution via controller/load-action-modules.js, function loadActionModules(). |
2Argencoders Notevil Project Notevil Project2Argencoders Notevil NotevilJun 17, 2026 Mar 17, 2022 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 This affects all versions of package notevil; all versions of package argencoders-notevil. It is vulnerable to Sandbox Escape leading to Prototype pollution. The package fails to restrict access to the main context, allo...Show more |
The jQuery deserialize library in Fisheye and Crucible before version 4.8.9 allowed remote attackers to to inject arbitrary HTML and/or JavaScript via a prototype pollution vulnerability. |
1Parseplatform 1Parse Server Jun 17, 2026 Mar 12, 2022 N/A· v4 10.0 CRITICAL· v3 7.5 HIGH· v2 Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in Parse Server. This vulnerability affects Parse Server in the default configurati...Show more |
1Jquery.cookie Project 1Jquery.cookie Jun 17, 2026 Mar 2, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 jQuery Cookie 1.4.1 is affected by prototype pollution, which can lead to DOM cross-site scripting (XSS). |
4Debian NetappNodejs+1 more11Debian Linux Mysql ClusterMysql Connectors+8 moreJun 17, 2026 Feb 24, 2022 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one proper...Show more |
1Object Extend Project 1Object Extend Jun 17, 2026 Feb 18, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The package object-extend from 0.0.0 are vulnerable to Prototype Pollution via object-extend. |
Prototype pollution vulnerability via .parse() in Plist before v3.0.4 allows attackers to cause a Denial of Service (DoS) and may lead to remote code execution. |
2Appwrite Litespeed.js Project2Appwrite Litespeed.jsJun 17, 2026 Feb 16, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 This affects the package litespeed.js before 0.3.12; the package appwrite/server-ce from 0.12.0 and before 0.12.2, before 0.11.1. When parsing the query string in the getJsonFromUrl function, the key that is set in the r...Show more |
This affects the package fastify-multipart before 5.3.1. By providing a name=constructor property it is still possible to crash the application. **Note:** This is a bypass of CVE-2020-8136 (https://security.snyk.io/vuln/...Show more |
superjson is a program to allow JavaScript expressions to be serialized to a superset of JSON. In versions prior to 1.8.1 superjson allows input to run arbitrary code on any server using superjson input without prior aut...Show more |
Frourio-express is a minimal full stack framework, for TypeScript. Frourio-express users who uses frourio-express version prior to v0.26.0 and integration with class-validator through `validators/` folder are subject to...Show more |
Frourio is a full stack framework, for TypeScript. Frourio users who uses frourio version prior to v0.26.0 and integration with class-validator through `validators/` folder are subject to a input validation vulnerability...Show more |
The package object-path-set before 1.0.2 are vulnerable to Prototype Pollution via the setPath method, as it allows an attacker to merge object prototypes into it. *Note:* This vulnerability derives from an incomplete fi...Show more |
This affects the package @strikeentco/set before 1.0.2. It allows an attacker to cause a denial of service and may lead to remote code execution. **Note:** This vulnerability derives from an incomplete fix in https://sec...Show more |
1Putil Merge Project 1Putil Merge Jun 17, 2026 Feb 4, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 This affects the package putil-merge before 3.8.0. The merge() function does not check the values passed into the argument. An attacker can supply a malicious value by adjusting the value to include the constructor prope...Show more |
Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0. |
The package keyget from 0.0.0 are vulnerable to Prototype Pollution via the methods set, push, and at which could allow an attacker to cause a denial of service and may lead to remote code execution. **Note:** This vulne...Show more |