← Back
CWE-1321

536 CVEs • Abstraction: Variant

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

JSON object

Loading...

CVEs (536)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Lodash
Oracle
18Banking Corporate Lending Process Management
Banking Credit Facilities Process ManagementBanking Extensibility Workbench+15 more
Jun 17, 2026
Jul 15, 2020
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
1Casperjs
1Casperjs
Jun 17, 2026
Jun 19, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In all versions of package casperjs, the mergeObjects utility function is susceptible to Prototype Pollution.
1Typo3
1Typo3
Jun 17, 2026
May 14, 2020
N/A· v4
10.0 CRITICAL· v3
6.4 MEDIUM· v2
In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, calling unserialize() on malicious user-submitted content can lead to modification of dynamically...Show more
In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, calling unserialize() on malicious user-submitted content can lead to modification of dynamically-determined object attributes and result in triggering deletion of an arbitrary directory in the file system, if it is writable for the web server. It can also trigger message submission via email using the identity of the web site (mail relay). Another insecure deserialization vulnerability is required to actually exploit mentioned aspects. This has been fixed in 9.5.17 and 10.4.2.Show less
1Fun Map Project
1Fun Map
Jun 17, 2026
Apr 28, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
fun-map through 3.3.1 is vulnerable to Prototype Pollution. The function assocInM could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.
1Idea
1Paypal Adaptive
Jun 17, 2026
Apr 23, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
paypal-adaptive through 0.4.2 manipulation of JavaScript objects resulting in Prototype Pollution. The PayPal function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
1Beakerbrowser
1Beaker
Jun 17, 2026
Apr 23, 2020
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
Beaker before 0.8.9 allows a sandbox escape, enabling system access and code execution. This occurs because Electron context isolation is not used, and therefore an attacker can conduct a prototype-pollution attack again...Show more
Beaker before 0.8.9 allows a sandbox escape, enabling system access and code execution. This occurs because Electron context isolation is not used, and therefore an attacker can conduct a prototype-pollution attack against the Electron internal messaging API.Show less
1Sds Project
1Sds
Jun 17, 2026
Apr 7, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
sds through 3.2.0 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of the 'Object.prototype' by abusing the 'set' function located in 'js/set.js'.
1Express Mock Middleware Project
1Express Mock Middleware
Jun 17, 2026
Apr 7, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
express-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tricked into adding or modifying properties of the `Object.prototype`. Exploitation of this vulnerabili...Show more
express-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tricked into adding or modifying properties of the `Object.prototype`. Exploitation of this vulnerability requires creation of a new directory where an attack code can be placed which will then be exported by `express-mock-middleware`. As such, this is considered to be a low risk.Show less
1Dot Project
1Dot
Jun 17, 2026
Apr 6, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.
1Confinit Project
1Confinit
Jun 17, 2026
Apr 6, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
confinit through 0.3.0 is vulnerable to Prototype Pollution.The 'setDeepProperty' function could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.
1Class Transformer Project
1Class Transformer
Jun 17, 2026
Apr 6, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
class-transformer before 0.3.1 allow attackers to perform Prototype Pollution. The classToPlainFromExist function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
1Ini Parser Project
1Ini Parser
Jun 17, 2026
Apr 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ini-parser through 0.0.2 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of Object.prototype using a '__proto__' payload.
1Yargs
1Yargs Parser
Jun 17, 2026
Mar 16, 2020
N/A· v4
5.3 MEDIUM· v3
4.6 MEDIUM· v2
yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload.
1Querymen Project
1Querymen
Jun 17, 2026
Mar 12, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
querymen prior to 2.1.4 allows modification of object properties. The parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. This could be abused for Prototype Pollut...Show more
querymen prior to 2.1.4 allows modification of object properties. The parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. This could be abused for Prototype Pollution attacks.Show less
2Opensuse
Substack
2Leap
Minimist
Jun 17, 2026
Mar 11, 2020
N/A· v4
5.6 MEDIUM· v3
6.8 MEDIUM· v2
minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
1Xcritical.software
1Utilitify
Jun 17, 2026
Mar 11, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
utilitify prior to 1.0.3 allows modification of object properties. The merge method could be tricked into adding or modifying properties of the Object.prototype.
3Debian
LinuxfoundationOracle
10Communications Application Session Controller
Communications Policy ManagementCommunications Pricing Design Center+7 more
Jun 17, 2026
Mar 10, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes,...Show more
In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values. This has been patched in versions 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2Show less
1Vega Project
1Vega
Jun 17, 2026
Mar 9, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
vega-util prior to 1.13.1 allows manipulation of object prototype. The 'vega.mergeConfig' method within vega-util could be tricked into adding or modifying properties of the Object.prototype.
1Dot Prop Project
1Dot Prop
Jun 17, 2026
Feb 4, 2020
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbitrary properties to JavaScript language constructs such as objects.
2Handlebars.js Project
Tenable
2Handlebars.js
Tenable.sc
Jun 17, 2026
Dec 20, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to exec...Show more
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.Show less