VYPR

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

VariantIncomplete

Description

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-180 · CAPEC-77

CVEs mapped to this weakness (612)

page 20 of 31
  • CVE-2021-23663MedDec 10, 2021
    risk 0.42cvss 6.5epss 0.01

    All versions of package sey are vulnerable to Prototype Pollution via the deepmerge() function.

  • CVE-2021-23561MedDec 10, 2021
    risk 0.42cvss 6.5epss 0.01

    All versions of package comb are vulnerable to Prototype Pollution via the deepMerge() function.

  • CVE-2021-23448MedOct 11, 2021
    risk 0.42cvss 6.5epss 0.01

    All versions of package config-handler are vulnerable to Prototype Pollution when loading config files.

  • CVE-2021-3805HigSep 17, 2021
    risk 0.42cvss 7.5epss 0.02

    object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

  • CVE-2021-32811HigAug 2, 2021
    risk 0.42cvss 7.5epss 0.02

    Zope is an open-source web application server. Zope versions prior to versions 4.6.3 and 5.3 have a remote code execution security issue. In order to be affected, one must use Python 3 for one's Zope deployment, run Zope 4 below version 4.6.3 or Zope 5 below version 5.3, and…

  • CVE-2020-24939HigJun 16, 2021
    risk 0.42cvss 7.5epss 0.02

    Prototype pollution in Stampit supermixer 1.0.3 allows an attacker to modify the prototype of a base object which can vary in severity depending on the implementation.

  • CVE-2021-23370HigApr 12, 2021
    risk 0.42cvss 7.5epss 0.02

    This affects the package swiper before 6.5.1.

  • CVE-2020-7771HigJan 4, 2021
    risk 0.42cvss 7.5epss 0.02

    The package asciitable.js before 1.0.3 are vulnerable to Prototype Pollution via the main function.

  • CVE-2020-28442HigDec 15, 2020
    risk 0.42cvss 7.5epss 0.02

    All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn function.

  • CVE-2020-7792HigDec 11, 2020
    risk 0.42cvss 7.5epss 0.02

    This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn 'mixes objects into the target object, recursively mixing existing child objects as well'. In both cases, the key used to access the…

  • CVE-2020-28268HigNov 15, 2020
    risk 0.42cvss 7.5epss 0.04

    Prototype pollution vulnerability in 'controlled-merge' versions 1.0.0 through 1.2.0 allows attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2020-7772HigNov 15, 2020
    risk 0.42cvss 7.5epss 0.03

    This affects the package doc-path before 2.1.2.

  • CVE-2020-28267HigNov 10, 2020
    risk 0.42cvss 7.5epss 0.02

    Prototype pollution vulnerability in '@strikeentco/set' version 1.0.0 allows attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2020-8268HigNov 9, 2020
    risk 0.42cvss 7.5epss 0.01

    Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor.

  • CVE-2020-7742HigOct 7, 2020
    risk 0.42cvss 7.5epss 0.02

    This affects the package simpl-schema before 1.10.2.

  • CVE-2020-7699HigJul 30, 2020
    risk 0.42cvss 7.5epss 0.05

    This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP request can lead to denial of service or arbitrary code execution.

  • CVE-2020-8203HigJul 15, 2020
    risk 0.42cvss 7.4epss 0.05

    Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.

  • CVE-2019-10768HigNov 19, 2019
    risk 0.42cvss 7.5epss 0.02

    In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload.

  • CVE-2019-10745HigAug 20, 2019
    risk 0.42cvss 7.5epss 0.01

    assign-deep is vulnerable to Prototype Pollution in versions before 0.4.8 and version 1.0.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using either a constructor or a _proto_ payload.

  • CVE-2026-15697MedJul 14, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in svgdotjs svg.js up to 3.2.5. This affects the function EventTarget.on of the file svgdotjs/svg.js of the component npm Package API. Performing a manipulation results in improperly controlled modification of object prototype attributes. The attack may…