CWE-1321
536 CVEs • Abstraction: Variant
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
CVEs (536)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The package bmoor before 0.10.1 are vulnerable to Prototype Pollution due to missing sanitization in set function. **Note:** This vulnerability derives from an incomplete fix in [CVE-2020-7736](https://security.snyk.io/v...Show more |
2Cached Path Relative Project Debian2Cached Path Relative Debian LinuxJun 17, 2026 Jan 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the p...Show more |
The package min-dash before 3.8.1 are vulnerable to Prototype Pollution via the set method due to missing enforcement of key types. |
All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector. |
The package extend2 before 1.0.1 are vulnerable to Prototype Pollution via the extend function due to unsafe recursive merge. |
All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector. |
OroPlatform is a PHP Business Application Platform. In affected versions by sending a specially crafted request, an attacker could inject properties into existing JavaScript language construct prototypes, such as objects...Show more |
All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn and the set functions. This is an incomplete fix of [CVE-2020-28442](https://snyk.io/vuln/SNYK-JS-JSDATA-1023655). |
3Debian LinuxfoundationOracle5Communications Policy Management Debian LinuxDojo+2 moreJun 17, 2026 Dec 17, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 All versions of package dojo are vulnerable to Prototype Pollution via the setObject function. |
1Merge Deep2 Project 1Merge Deep2 Jun 17, 2026 Dec 10, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 All versions of package merge-deep2 are vulnerable to Prototype Pollution via the mergeDeep() function. |
All versions of package sey are vulnerable to Prototype Pollution via the deepmerge() function. |
All versions of package comb are vulnerable to Prototype Pollution via the deepMerge() function. |
utils.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
Nodebb is an open source Node.js based forum software. In affected versions a prototype pollution vulnerability in the uploader module allowed a malicious user to inject arbitrary data (i.e. javascript) into the DOM, the...Show more |
1Algolia 1Algoliasearch Helper Jun 17, 2026 Nov 19, 2021 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 The package algoliasearch-helper before 3.6.2 are vulnerable to Prototype Pollution due to use of the merge function in src/SearchParameters/index.jsSearchParameters._parseNumbers without any protection against prototype...Show more |
2Debian Json Schema Project2Debian Linux Json SchemaJun 17, 2026 Nov 13, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
This affects all versions of package x-assign. The global proto object can be polluted using the __proto__ object. |
This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to execution of arbitrary code on the host machine. |
1Config Handler Project 1Config Handler Jun 17, 2026 Oct 11, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 All versions of package config-handler are vulnerable to Prototype Pollution when loading config files. |
aurelia-path is part of the Aurelia platform and contains utilities for path manipulation. There is a prototype pollution vulnerability in aurelia-path before version 1.1.7. The vulnerability exposes Aurelia application...Show more |