CWE-1321
536 CVEs • Abstraction: Variant
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
CVEs (536)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
ZRender is a lightweight graphic library providing 2d draw for Apache ECharts. In versions prior to 5.2.1, using `merge` and `clone` helper methods in the `src/core/util.ts` module results in prototype pollution. It affe...Show more |
1Cookiex Deep Project 1Cookiex Deep Jun 17, 2026 Sep 17, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 This affects all versions of package @cookiex/deep. The global proto object can be polluted using the __proto__ object. |
2Debian Object Path Project2Debian Linux Object PathJun 17, 2026 Sep 17, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
Jitsi Meet is an open source video conferencing application. Versions prior to 2.0.6173 are vulnerable to client-side cross-site scripting via injecting properties into JSON objects that were not properly escaped. There...Show more |
1Xml Body Parser Project 1Xml Body Parser Jun 17, 2026 Sep 13, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 body-parser-xml is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
merge is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
objection.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
immer is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
1Merge Change Project 1Merge Change Jun 17, 2026 Aug 11, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 All versions of package merge-change are vulnerable to Prototype Pollution via the utils.set function. |
1Open Graph Project 1Open Graph Jun 17, 2026 Aug 8, 2021 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 This affects the package open-graph before 0.2.6. The function parse could be tricked into adding or modifying properties of Object.prototype using a __proto__ or constructor payload. |
Zope is an open-source web application server. Zope versions prior to versions 4.6.3 and 5.3 have a remote code execution security issue. In order to be affected, one must use Python 3 for one's Zope deployment, run Zope...Show more |
The module `AccessControl` defines security policies for Python code used in restricted code within Zope applications. Restricted code is any code that resides in Zope's object database, such as the contents of `Script (...Show more |
1Deepmergefn Project 1Deepmergefn Jun 17, 2026 Jul 28, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 All versions of package deepmergefn are vulnerable to Prototype Pollution via deepMerge function. |
This affects the package com.graphhopper:graphhopper-web-bundle before 3.2, from 4.0-pre1 and before 4.0. The URL parser could be tricked into adding or modifying properties of Object.prototype using a constructor or __p...Show more |
1Putil Merge Project 1Putil Merge Jun 17, 2026 Jul 14, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Prototype pollution vulnerability in 'putil-merge' versions1.0.0 through 3.6.6 allows attacker to cause a denial of service and may lead to remote code execution. |
1Just Safe Set Project 1Just Safe Set Jun 17, 2026 Jul 7, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Prototype pollution vulnerability in ‘just-safe-set’ versions 1.0.0 through 2.2.1 allows an attacker to cause a denial of service and may lead to remote code execution. |
1Ts Nodash Project 1Ts Nodash Jun 17, 2026 Jul 2, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 All versions of package ts-nodash are vulnerable to Prototype Pollution via the Merge() function due to lack of validation input. |
1Record Like Deep Assign Project 1Record Like Deep Assign Jun 17, 2026 Jul 2, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 All versions of package record-like-deep-assign are vulnerable to Prototype Pollution via the main functionality. |
think-helper defines a set of helper functions for ThinkJS. In versions of think-helper prior to 1.1.3, the software receives input from an upstream component that specifies attributes that are to be initialized or updat...Show more |
All versions of package lutils are vulnerable to Prototype Pollution via the main (merge) function. |