← Back
CWE-1321

536 CVEs • Abstraction: Variant

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

JSON object

Loading...

CVEs (536)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bmoor Project
1Bmoor
Jun 17, 2026
Jan 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The package bmoor before 0.10.1 are vulnerable to Prototype Pollution due to missing sanitization in set function. **Note:** This vulnerability derives from an incomplete fix in [CVE-2020-7736](https://security.snyk.io/v...Show more
The package bmoor before 0.10.1 are vulnerable to Prototype Pollution due to missing sanitization in set function. **Note:** This vulnerability derives from an incomplete fix in [CVE-2020-7736](https://security.snyk.io/vuln/SNYK-JS-BMOOR-598664)Show less
2Cached Path Relative Project
Debian
2Cached Path Relative
Debian Linux
Jun 17, 2026
Jan 21, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the p...Show more
The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the object is used to create the cached relative path. When using the origin path as __proto__, the attribute of the object is accessed instead of a path. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-CACHEDPATHRELATIVE-72573Show less
1Camunda
1Min Dash
Jun 17, 2026
Jan 21, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The package min-dash before 3.8.1 are vulnerable to Prototype Pollution via the set method due to missing enforcement of key types.
1Agoric
1Realms Shim
Jun 17, 2026
Jan 10, 2022
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.
1Eggjs
1Extend2
Jun 17, 2026
Jan 10, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The package extend2 before 1.0.1 are vulnerable to Prototype Pollution via the extend function due to unsafe recursive merge.
1Agoric
1Realms Shim
Jun 17, 2026
Jan 10, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.
1Oroinc
1Oroplatform
Jun 17, 2026
Jan 4, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
OroPlatform is a PHP Business Application Platform. In affected versions by sending a specially crafted request, an attacker could inject properties into existing JavaScript language construct prototypes, such as objects...Show more
OroPlatform is a PHP Business Application Platform. In affected versions by sending a specially crafted request, an attacker could inject properties into existing JavaScript language construct prototypes, such as objects. Later this injection may lead to JS code execution by libraries that are vulnerable to Prototype Pollution. This issue has been patched in version 4.2.8. Users unable to upgrade may configure a firewall to drop requests containing next strings: `__proto__` , `constructor[prototype]`, and `constructor.prototype` to mitigate this issue.Show less
1Js Data
1Js Data
Jun 17, 2026
Dec 24, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn and the set functions. This is an incomplete fix of [CVE-2020-28442](https://snyk.io/vuln/SNYK-JS-JSDATA-1023655).
3Debian
LinuxfoundationOracle
5Communications Policy Management
Debian LinuxDojo+2 more
Jun 17, 2026
Dec 17, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
1Merge Deep2 Project
1Merge Deep2
Jun 17, 2026
Dec 10, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
All versions of package merge-deep2 are vulnerable to Prototype Pollution via the mergeDeep() function.
1Sey Project
1Sey
Jun 17, 2026
Dec 10, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
All versions of package sey are vulnerable to Prototype Pollution via the deepmerge() function.
1C2fo
1Comb
Jun 17, 2026
Dec 10, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
All versions of package comb are vulnerable to Prototype Pollution via the deepMerge() function.
1Utils.js Project
1Utils.js
Jun 17, 2026
Dec 8, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
utils.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
1Nodebb
1Nodebb
Jun 17, 2026
Nov 29, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Nodebb is an open source Node.js based forum software. In affected versions a prototype pollution vulnerability in the uploader module allowed a malicious user to inject arbitrary data (i.e. javascript) into the DOM, the...Show more
Nodebb is an open source Node.js based forum software. In affected versions a prototype pollution vulnerability in the uploader module allowed a malicious user to inject arbitrary data (i.e. javascript) into the DOM, theoretically allowing for an account takeover when used in conjunction with a path traversal vulnerability disclosed at the same time as this report. The vulnerability has been patched as of v1.18.5. Users are advised to upgrade as soon as possible.Show less
1Algolia
1Algoliasearch Helper
Jun 17, 2026
Nov 19, 2021
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
The package algoliasearch-helper before 3.6.2 are vulnerable to Prototype Pollution due to use of the merge function in src/SearchParameters/index.jsSearchParameters._parseNumbers without any protection against prototype...Show more
The package algoliasearch-helper before 3.6.2 are vulnerable to Prototype Pollution due to use of the merge function in src/SearchParameters/index.jsSearchParameters._parseNumbers without any protection against prototype properties. Note that this vulnerability is only exploitable if the implementation allows users to define arbitrary search patterns.Show less
2Debian
Json Schema Project
2Debian Linux
Json Schema
Jun 17, 2026
Nov 13, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
1Binaryops
1X Assign
Jun 17, 2026
Oct 20, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
This affects all versions of package x-assign. The global proto object can be polluted using the __proto__ object.
1Vm2 Project
1Vm2
Jun 17, 2026
Oct 18, 2021
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to execution of arbitrary code on the host machine.
1Config Handler Project
1Config Handler
Jun 17, 2026
Oct 11, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
All versions of package config-handler are vulnerable to Prototype Pollution when loading config files.
1Bluespire
1Aurelia Path
Jun 17, 2026
Sep 27, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
aurelia-path is part of the Aurelia platform and contains utilities for path manipulation. There is a prototype pollution vulnerability in aurelia-path before version 1.1.7. The vulnerability exposes Aurelia application...Show more
aurelia-path is part of the Aurelia platform and contains utilities for path manipulation. There is a prototype pollution vulnerability in aurelia-path before version 1.1.7. The vulnerability exposes Aurelia application that uses `aurelia-path` package to parse a string. The majority of this will be Aurelia applications that employ the `aurelia-router` package. An example is this could allow an attacker to change the prototype of base object class `Object` by tricking an application to parse the following URL: `https://aurelia.io/blog/?__proto__[asdf]=asdf`. The problem is patched in version `1.1.7`.Show less