CWE-1321
536 CVEs • Abstraction: Variant
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
CVEs (536)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Lodash Oracle18Banking Corporate Lending Process Management Banking Credit Facilities Process ManagementBanking Extensibility Workbench+15 moreJun 17, 2026 Jul 15, 2020 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20. |
In all versions of package casperjs, the mergeObjects utility function is susceptible to Prototype Pollution. |
In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, calling unserialize() on malicious user-submitted content can lead to modification of dynamically...Show more |
fun-map through 3.3.1 is vulnerable to Prototype Pollution. The function assocInM could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload. |
paypal-adaptive through 0.4.2 manipulation of JavaScript objects resulting in Prototype Pollution. The PayPal function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload. |
Beaker before 0.8.9 allows a sandbox escape, enabling system access and code execution. This occurs because Electron context isolation is not used, and therefore an attacker can conduct a prototype-pollution attack again...Show more |
sds through 3.2.0 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of the 'Object.prototype' by abusing the 'set' function located in 'js/set.js'. |
1Express Mock Middleware Project 1Express Mock Middleware Jun 17, 2026 Apr 7, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 express-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tricked into adding or modifying properties of the `Object.prototype`. Exploitation of this vulnerabili...Show more |
eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload. |
confinit through 0.3.0 is vulnerable to Prototype Pollution.The 'setDeepProperty' function could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload. |
1Class Transformer Project 1Class Transformer Jun 17, 2026 Apr 6, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 class-transformer before 0.3.1 allow attackers to perform Prototype Pollution. The classToPlainFromExist function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload. |
1Ini Parser Project 1Ini Parser Jun 17, 2026 Apr 2, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ini-parser through 0.0.2 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of Object.prototype using a '__proto__' payload. |
yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload. |
querymen prior to 2.1.4 allows modification of object properties. The parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. This could be abused for Prototype Pollut...Show more |
2Opensuse Substack2Leap MinimistJun 17, 2026 Mar 11, 2020 N/A· v4 5.6 MEDIUM· v3 6.8 MEDIUM· v2 minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload. |
1Xcritical.software 1Utilitify Jun 17, 2026 Mar 11, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 utilitify prior to 1.0.3 allows modification of object properties. The merge method could be tricked into adding or modifying properties of the Object.prototype. |
3Debian LinuxfoundationOracle10Communications Application Session Controller Communications Policy ManagementCommunications Pricing Design Center+7 moreJun 17, 2026 Mar 10, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes,...Show more |
vega-util prior to 1.13.1 allows manipulation of object prototype. The 'vega.mergeConfig' method within vega-util could be tricked into adding or modifying properties of the Object.prototype. |
Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbitrary properties to JavaScript language constructs such as objects. |
2Handlebars.js Project Tenable2Handlebars.js Tenable.scJun 17, 2026 Dec 20, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to exec...Show more |