VYPR

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

VariantIncomplete

Description

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-180 · CAPEC-77

CVEs mapped to this weakness (612)

page 1 of 31
  • CVE-2019-0230CriSep 14, 2020
    risk 0.74cvss 9.8epss 0.97

    Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.

  • CVE-2026-34621HigKEVApr 11, 2026
    risk 0.68cvss 8.6epss 0.07

    Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user.…

  • CVE-2011-10019CriAug 13, 2025
    risk 0.67cvss 9.8epss 0.04

    Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to properly sanitize input passed via the search[send][] parameter, which is dynamically invoked using Ruby’s send method. This allows…

  • CVE-2026-44005CriMay 13, 2026
    risk 0.65cvss 10.0epss 0.01

    vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes into the underlying host objects with otherReflectSet() and otherReflectDefineProperty(), which lets…

  • CVE-2020-12079CriApr 23, 2020
    risk 0.65cvss 10.0epss 0.02

    Beaker before 0.8.9 allows a sandbox escape, enabling system access and code execution. This occurs because Electron context isolation is not used, and therefore an attacker can conduct a prototype-pollution attack against the Electron internal messaging API.

  • CVE-2026-44791CriJun 23, 2026
    risk 0.64cvss 9.9epss 0.01

    n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could bypass the patch for CVE-2026-42232 in the XML node. When combined with other nodes, this could lead to RCE on the…

  • CVE-2026-44789CriJun 23, 2026
    risk 0.64cvss 9.9epss 0.01

    n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via an unvalidated pagination parameter in the HTTP Request node. Combined with…

  • CVE-2025-63704CriMay 7, 2026
    risk 0.64cvss 9.8epss 0.00

    NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly created object.

  • CVE-2025-63703CriMay 7, 2026
    risk 0.64cvss 9.8epss 0.00

    npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js().

  • CVE-2025-57321CriSep 24, 2025
    risk 0.64cvss 9.8epss 0.00

    A Prototype Pollution vulnerability in the util-deps.addFileDepend function of magix-combine-ex versions thru 1.2.10 allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.

  • CVE-2025-57347CriSep 24, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability exists in the 'dagre-d3-es' Node.js package version 7.0.9, specifically within the 'bk' module's addConflict function, which fails to properly sanitize user-supplied input during property assignment operations. This flaw allows attackers to exploit prototype…

  • CVE-2024-38985CriMar 28, 2025
    risk 0.64cvss 9.8epss 0.01

    janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() method at setIn (lib/index.js:90). This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary…

  • CVE-2024-24292CriMar 28, 2025
    risk 0.64cvss 9.8epss 0.01

    A Prototype Pollution issue in Aliconnect /sdk v.0.0.6 allows an attacker to execute arbitrary code via the aim function in the aim.js component.

  • CVE-2025-25015CriMar 5, 2025
    risk 0.64cvss 9.9epss 0.01

    Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP requests. In Kibana versions >= 8.15.0 and < 8.17.1, this is exploitable by users with the Viewer role. In Kibana versions 8.17.1 and 8.17.2 , this is only…

  • CVE-2024-56059CriDec 18, 2024
    risk 0.64cvss 9.8epss 0.02

    Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in farinspace Partners partners allows Object Injection.This issue affects Partners: from n/a through <= 0.2.0.

  • CVE-2024-52441CriNov 20, 2024
    risk 0.64cvss 9.8epss 0.01

    Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Rajesh Thanoch Quick Learn quick-learn allows Object Injection.This issue affects Quick Learn: from n/a through <= 1.0.1.

  • CVE-2024-45435CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.01

    Chartist 1.x through 1.3.0 allows Prototype Pollution via the extend function.

  • CVE-2024-38983CriJul 30, 2024
    risk 0.64cvss 9.8epss 0.01

    Prototype Pollution in alykoshin mini-deep-assign v0.0.8 allows an attacker to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via the _assign() method at (/lib/index.js:91)

  • CVE-2024-39012CriJul 30, 2024
    risk 0.64cvss 9.8epss 0.01

    ais-ltd strategyen v0.4.0 was discovered to contain a prototype pollution via the function mergeObjects. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-39011CriJul 30, 2024
    risk 0.64cvss 9.8epss 0.01

    Prototype Pollution in chargeover redoc v2.0.9-rc.69 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via the function mergeObjects.