← Back
CWE-1321

536 CVEs • Abstraction: Variant

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

JSON object

Loading...

CVEs (536)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Stampit
1Supermixer
Jun 17, 2026
Jun 16, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Prototype pollution in Stampit supermixer 1.0.3 allows an attacker to modify the prototype of a base object which can vary in severity depending on the implementation.
1Nedb Project
1Nedb
Jun 17, 2026
Jun 15, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
This affects all versions of package nedb. The library could be tricked into adding or modifying properties of Object.prototype using a __proto__ or constructor.prototype payload.
1Set Getter Project
1Set Getter
Jun 17, 2026
Jun 10, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Prototype pollution vulnerability in 'set-getter' version 0.1.0 allows an attacker to cause a denial of service and may lead to remote code execution.
1Expand Hash Project
1Expand Hash
Jun 17, 2026
Jun 10, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Prototype pollution vulnerability in 'expand-hash' versions 0.1.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
1Nestie Project
1Nestie
Jun 17, 2026
Jun 3, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Prototype pollution vulnerability in 'nestie' versions 0.0.0 through 1.0.0 allows an attacker to cause a denial of service and may lead to remote code execution.
2Merge Deep Project
Netapp
2E Series Performance Analyzer
Merge Deep
Jun 17, 2026
Jun 2, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus faci...Show more
The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-pollution attacks against applications using this library.Show less
1Js Extend Project
1Js Extend
Jun 17, 2026
May 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Prototype pollution vulnerability in 'js-extend' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
1Nconf Toml Project
1Nconf Toml
Jun 17, 2026
May 25, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Prototype pollution vulnerability in `nconf-toml` versions 0.0.1 through 0.0.2 allows an attacker to cause a denial of service and may lead to remote code execution.
1Deep Defaults Project
1Deep Defaults
Jun 17, 2026
May 25, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Prototype pollution vulnerability in 'deep-defaults' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.
1101 Project
1101
Jun 17, 2026
May 14, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Prototype pollution vulnerability in '101' versions 1.0.0 through 1.6.3 allows an attacker to cause a denial of service and may lead to remote code execution.
1Deep Override Project
1Deep Override
Jun 17, 2026
May 14, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Prototype pollution vulnerability in 'deep-override' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
2Handlebarsjs
Netapp
2E Series Performance Analyzer
Handlebars
Jun 17, 2026
May 4, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.
1Adaltas
1Mixme
Jul 9, 2026
May 3, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the...Show more
In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This will put the availability of the program at risk causing a potential denial of service (DoS).Show less
1Manta
1Safe Obj
Jun 17, 2026
Apr 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Prototype pollution vulnerability in 'safe-obj' versions 1.0.0 through 1.0.2 allows an attacker to cause a denial of service and may lead to remote code execution.
1Safe Flat Project
1Safe Flat
Jun 17, 2026
Apr 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Prototype pollution vulnerability in 'safe-flat' versions 2.0.0 through 2.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
1Purl Project
1Purl
Jun 17, 2026
Apr 23, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in purl 2.3.2 allows a malicious user to inject properties into Object.prototype.
1Jquery Bbq Project
1Jquery Bbq
Jun 17, 2026
Apr 23, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-bbq 1.2.1 allows a malicious user to inject properties into Object.prototype.
1Backbone Query Parameters Project
1Backbone Query Parameters
Jun 17, 2026
Apr 23, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in backbone-query-parameters 0.4.0 allows a malicious user to inject properties into Object.prototype.
1Jquery Plugin Query Object Project
1Jquery Plugin Query Object
Jun 17, 2026
Apr 23, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-plugin-query-object 2.2.3 allows a malicious user to inject properties into Object.prototype.
1Mootools
1Mootools More
Jun 17, 2026
Apr 23, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in mootools-more 1.6.0 allows a malicious user to inject properties into Object.prototype.