← Back
CWE-1321

572 CVEs • Abstraction: Variant

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

JSON object

Loading...

CVEs (572)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Idea
1Paypal Adaptive
Jun 17, 2026
Apr 23, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
paypal-adaptive through 0.4.2 manipulation of JavaScript objects resulting in Prototype Pollution. The PayPal function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
1Beakerbrowser
1Beaker
Jun 17, 2026
Apr 23, 2020
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
Beaker before 0.8.9 allows a sandbox escape, enabling system access and code execution. This occurs because Electron context isolation is not used, and therefore an attacker can conduct a prototype-pollution attack again...Show more
Beaker before 0.8.9 allows a sandbox escape, enabling system access and code execution. This occurs because Electron context isolation is not used, and therefore an attacker can conduct a prototype-pollution attack against the Electron internal messaging API.Show less
1Sds Project
1Sds
Jun 17, 2026
Apr 7, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
sds through 3.2.0 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of the 'Object.prototype' by abusing the 'set' function located in 'js/set.js'.
1Express Mock Middleware Project
1Express Mock Middleware
Jun 17, 2026
Apr 7, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
express-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tricked into adding or modifying properties of the `Object.prototype`. Exploitation of this vulnerabili...Show more
express-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tricked into adding or modifying properties of the `Object.prototype`. Exploitation of this vulnerability requires creation of a new directory where an attack code can be placed which will then be exported by `express-mock-middleware`. As such, this is considered to be a low risk.Show less
1Dot Project
1Dot
Jun 17, 2026
Apr 6, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.
1Confinit Project
1Confinit
Jun 17, 2026
Apr 6, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
confinit through 0.3.0 is vulnerable to Prototype Pollution.The 'setDeepProperty' function could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.
1Class Transformer Project
1Class Transformer
Jun 17, 2026
Apr 6, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
class-transformer before 0.3.1 allow attackers to perform Prototype Pollution. The classToPlainFromExist function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
1Ini Parser Project
1Ini Parser
Jun 17, 2026
Apr 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ini-parser through 0.0.2 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of Object.prototype using a '__proto__' payload.
1Yargs
1Yargs Parser
Jun 17, 2026
Mar 16, 2020
N/A· v4
5.3 MEDIUM· v3
4.6 MEDIUM· v2
yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload.
1Querymen Project
1Querymen
Jun 17, 2026
Mar 12, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
querymen prior to 2.1.4 allows modification of object properties. The parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. This could be abused for Prototype Pollut...Show more
querymen prior to 2.1.4 allows modification of object properties. The parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. This could be abused for Prototype Pollution attacks.Show less
2Opensuse
Substack
2Leap
Minimist
Jun 17, 2026
Mar 11, 2020
N/A· v4
5.6 MEDIUM· v3
6.8 MEDIUM· v2
minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
1Xcritical.software
1Utilitify
Jun 17, 2026
Mar 11, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
utilitify prior to 1.0.3 allows modification of object properties. The merge method could be tricked into adding or modifying properties of the Object.prototype.
3Debian
LinuxfoundationOracle
10Communications Application Session Controller
Communications Policy ManagementCommunications Pricing Design Center+7 more
Jun 17, 2026
Mar 10, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes,...Show more
In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values. This has been patched in versions 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2Show less
1Vega Project
1Vega
Jun 17, 2026
Mar 9, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
vega-util prior to 1.13.1 allows manipulation of object prototype. The 'vega.mergeConfig' method within vega-util could be tricked into adding or modifying properties of the Object.prototype.
1Dot Prop Project
1Dot Prop
Jun 17, 2026
Feb 4, 2020
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbitrary properties to JavaScript language constructs such as objects.
2Handlebars.js Project
Tenable
2Handlebars.js
Tenable.sc
Jun 17, 2026
Dec 20, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to exec...Show more
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.Show less
1Angularjs
1Angularjs
Jun 17, 2026
Nov 19, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload.
1Sugarcrm
1Sugarcrm
Jun 17, 2026
Oct 7, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the UpgradeWizard module by an Admin user.
1Sugarcrm
1Sugarcrm
Jun 17, 2026
Oct 7, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Import module by a Regular user.
1Sugarcrm
1Sugarcrm
Jun 17, 2026
Oct 7, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Administration module by an Admin user.