CWE-1321
536 CVEs • Abstraction: Variant
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
CVEs (536)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Prototype pollution in Stampit supermixer 1.0.3 allows an attacker to modify the prototype of a base object which can vary in severity depending on the implementation. |
This affects all versions of package nedb. The library could be tricked into adding or modifying properties of Object.prototype using a __proto__ or constructor.prototype payload. |
1Set Getter Project 1Set Getter Jun 17, 2026 Jun 10, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Prototype pollution vulnerability in 'set-getter' version 0.1.0 allows an attacker to cause a denial of service and may lead to remote code execution. |
1Expand Hash Project 1Expand Hash Jun 17, 2026 Jun 10, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Prototype pollution vulnerability in 'expand-hash' versions 0.1.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution. |
Prototype pollution vulnerability in 'nestie' versions 0.0.0 through 1.0.0 allows an attacker to cause a denial of service and may lead to remote code execution. |
2Merge Deep Project Netapp2E Series Performance Analyzer Merge DeepJun 17, 2026 Jun 2, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus faci...Show more |
1Js Extend Project 1Js Extend Jun 17, 2026 May 26, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Prototype pollution vulnerability in 'js-extend' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution. |
1Nconf Toml Project 1Nconf Toml Jun 17, 2026 May 25, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Prototype pollution vulnerability in `nconf-toml` versions 0.0.1 through 0.0.2 allows an attacker to cause a denial of service and may lead to remote code execution. |
1Deep Defaults Project 1Deep Defaults Jun 17, 2026 May 25, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Prototype pollution vulnerability in 'deep-defaults' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution. |
Prototype pollution vulnerability in '101' versions 1.0.0 through 1.6.3 allows an attacker to cause a denial of service and may lead to remote code execution. |
1Deep Override Project 1Deep Override Jun 17, 2026 May 14, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Prototype pollution vulnerability in 'deep-override' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution. |
2Handlebarsjs Netapp2E Series Performance Analyzer HandlebarsJun 17, 2026 May 4, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source. |
In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the...Show more |
Prototype pollution vulnerability in 'safe-obj' versions 1.0.0 through 1.0.2 allows an attacker to cause a denial of service and may lead to remote code execution. |
1Safe Flat Project 1Safe Flat Jun 17, 2026 Apr 26, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Prototype pollution vulnerability in 'safe-flat' versions 2.0.0 through 2.0.1 allows an attacker to cause a denial of service and may lead to remote code execution. |
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in purl 2.3.2 allows a malicious user to inject properties into Object.prototype. |
1Jquery Bbq Project 1Jquery Bbq Jun 17, 2026 Apr 23, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-bbq 1.2.1 allows a malicious user to inject properties into Object.prototype. |
1Backbone Query Parameters Project 1Backbone Query Parameters Jun 17, 2026 Apr 23, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in backbone-query-parameters 0.4.0 allows a malicious user to inject properties into Object.prototype. |
1Jquery Plugin Query Object Project 1Jquery Plugin Query Object Jun 17, 2026 Apr 23, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-plugin-query-object 2.2.3 allows a malicious user to inject properties into Object.prototype. |
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in mootools-more 1.6.0 allows a malicious user to inject properties into Object.prototype. |