CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Description
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-180 · CAPEC-77
CVEs mapped to this weakness (612)
page 20 of 31| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-23663 | Med | 0.42 | 6.5 | 0.01 | Dec 10, 2021 | All versions of package sey are vulnerable to Prototype Pollution via the deepmerge() function. | ||
| CVE-2021-23561 | — | Med | 0.42 | 6.5 | 0.01 | Dec 10, 2021 | All versions of package comb are vulnerable to Prototype Pollution via the deepMerge() function. | |
| CVE-2021-23448 | Med | 0.42 | 6.5 | 0.01 | Oct 11, 2021 | All versions of package config-handler are vulnerable to Prototype Pollution when loading config files. | ||
| CVE-2021-3805 | Hig | 0.42 | 7.5 | 0.02 | Sep 17, 2021 | object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | ||
| CVE-2021-32811 | Hig | 0.42 | 7.5 | 0.02 | Aug 2, 2021 | Zope is an open-source web application server. Zope versions prior to versions 4.6.3 and 5.3 have a remote code execution security issue. In order to be affected, one must use Python 3 for one's Zope deployment, run Zope 4 below version 4.6.3 or Zope 5 below version 5.3, and… | ||
| CVE-2020-24939 | Hig | 0.42 | 7.5 | 0.02 | Jun 16, 2021 | Prototype pollution in Stampit supermixer 1.0.3 allows an attacker to modify the prototype of a base object which can vary in severity depending on the implementation. | ||
| CVE-2021-23370 | Hig | 0.42 | 7.5 | 0.02 | Apr 12, 2021 | This affects the package swiper before 6.5.1. | ||
| CVE-2020-7771 | Hig | 0.42 | 7.5 | 0.02 | Jan 4, 2021 | The package asciitable.js before 1.0.3 are vulnerable to Prototype Pollution via the main function. | ||
| CVE-2020-28442 | Hig | 0.42 | 7.5 | 0.02 | Dec 15, 2020 | All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn function. | ||
| CVE-2020-7792 | Hig | 0.42 | 7.5 | 0.02 | Dec 11, 2020 | This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn 'mixes objects into the target object, recursively mixing existing child objects as well'. In both cases, the key used to access the… | ||
| CVE-2020-28268 | Hig | 0.42 | 7.5 | 0.04 | Nov 15, 2020 | Prototype pollution vulnerability in 'controlled-merge' versions 1.0.0 through 1.2.0 allows attacker to cause a denial of service and may lead to remote code execution. | ||
| CVE-2020-7772 | Hig | 0.42 | 7.5 | 0.03 | Nov 15, 2020 | This affects the package doc-path before 2.1.2. | ||
| CVE-2020-28267 | Hig | 0.42 | 7.5 | 0.02 | Nov 10, 2020 | Prototype pollution vulnerability in '@strikeentco/set' version 1.0.0 allows attacker to cause a denial of service and may lead to remote code execution. | ||
| CVE-2020-8268 | Hig | 0.42 | 7.5 | 0.01 | Nov 9, 2020 | Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor. | ||
| CVE-2020-7742 | Hig | 0.42 | 7.5 | 0.02 | Oct 7, 2020 | This affects the package simpl-schema before 1.10.2. | ||
| CVE-2020-7699 | Hig | 0.42 | 7.5 | 0.05 | Jul 30, 2020 | This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP request can lead to denial of service or arbitrary code execution. | ||
| CVE-2020-8203 | Hig | 0.42 | 7.4 | 0.05 | Jul 15, 2020 | Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20. | ||
| CVE-2019-10768 | Hig | 0.42 | 7.5 | 0.02 | Nov 19, 2019 | In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload. | ||
| CVE-2019-10745 | Hig | 0.42 | 7.5 | 0.01 | Aug 20, 2019 | assign-deep is vulnerable to Prototype Pollution in versions before 0.4.8 and version 1.0.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using either a constructor or a _proto_ payload. | ||
| CVE-2026-15697 | Med | 0.41 | 6.3 | 0.00 | Jul 14, 2026 | A vulnerability was found in svgdotjs svg.js up to 3.2.5. This affects the function EventTarget.on of the file svgdotjs/svg.js of the component npm Package API. Performing a manipulation results in improperly controlled modification of object prototype attributes. The attack may… |
- risk 0.42cvss 6.5epss 0.01
All versions of package sey are vulnerable to Prototype Pollution via the deepmerge() function.
- risk 0.42cvss 6.5epss 0.01
All versions of package comb are vulnerable to Prototype Pollution via the deepMerge() function.
- risk 0.42cvss 6.5epss 0.01
All versions of package config-handler are vulnerable to Prototype Pollution when loading config files.
- risk 0.42cvss 7.5epss 0.02
object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
- risk 0.42cvss 7.5epss 0.02
Zope is an open-source web application server. Zope versions prior to versions 4.6.3 and 5.3 have a remote code execution security issue. In order to be affected, one must use Python 3 for one's Zope deployment, run Zope 4 below version 4.6.3 or Zope 5 below version 5.3, and…
- risk 0.42cvss 7.5epss 0.02
Prototype pollution in Stampit supermixer 1.0.3 allows an attacker to modify the prototype of a base object which can vary in severity depending on the implementation.
- risk 0.42cvss 7.5epss 0.02
This affects the package swiper before 6.5.1.
- risk 0.42cvss 7.5epss 0.02
The package asciitable.js before 1.0.3 are vulnerable to Prototype Pollution via the main function.
- risk 0.42cvss 7.5epss 0.02
All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn function.
- risk 0.42cvss 7.5epss 0.02
This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn 'mixes objects into the target object, recursively mixing existing child objects as well'. In both cases, the key used to access the…
- risk 0.42cvss 7.5epss 0.04
Prototype pollution vulnerability in 'controlled-merge' versions 1.0.0 through 1.2.0 allows attacker to cause a denial of service and may lead to remote code execution.
- risk 0.42cvss 7.5epss 0.03
This affects the package doc-path before 2.1.2.
- risk 0.42cvss 7.5epss 0.02
Prototype pollution vulnerability in '@strikeentco/set' version 1.0.0 allows attacker to cause a denial of service and may lead to remote code execution.
- risk 0.42cvss 7.5epss 0.01
Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor.
- risk 0.42cvss 7.5epss 0.02
This affects the package simpl-schema before 1.10.2.
- risk 0.42cvss 7.5epss 0.05
This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP request can lead to denial of service or arbitrary code execution.
- risk 0.42cvss 7.4epss 0.05
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
- risk 0.42cvss 7.5epss 0.02
In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload.
- risk 0.42cvss 7.5epss 0.01
assign-deep is vulnerable to Prototype Pollution in versions before 0.4.8 and version 1.0.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using either a constructor or a _proto_ payload.
- risk 0.41cvss 6.3epss 0.00
A vulnerability was found in svgdotjs svg.js up to 3.2.5. This affects the function EventTarget.on of the file svgdotjs/svg.js of the component npm Package API. Performing a manipulation results in improperly controlled modification of object prototype attributes. The attack may…