VYPR

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

VariantIncomplete

Description

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-180 · CAPEC-77

CVEs mapped to this weakness (612)

page 25 of 31
  • CVE-2025-57324MedSep 24, 2025
    risk 0.35cvss 6.5epss 0.00

    parse is a package designed to parse JavaScript SDK. A Prototype Pollution vulnerability in the SingleInstanceStateController.initializeState function of parse version 5.3.0 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload,…

  • CVE-2024-57082MedFeb 5, 2025
    risk 0.35cvss 6.5epss 0.00

    A prototype pollution in the lib.createUploader function of @rpldy/uploader v1.8.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

  • CVE-2024-21509MedApr 10, 2024
    risk 0.35cvss 6.5epss 0.01

    Versions of the package mysql2 before 3.9.4 are vulnerable to Prototype Poisoning due to insecure results object creation and improper user input sanitization passed through parserFn in text_parser.js and binary_parser.js.

  • CVE-2023-26920MedDec 12, 2023
    risk 0.35cvss 6.5epss 0.01

    fast-xml-parser before 4.1.2 allows __proto__ for Prototype Pollution.

  • CVE-2023-26136MedJul 1, 2023
    risk 0.35cvss 6.5epss 0.03

    Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized.

  • CVE-2021-23432MedAug 24, 2021
    risk 0.35cvss 5.4epss 0.01

    This affects all versions of package mootools. This is due to the ability to pass untrusted input to Object.merge()

  • CVE-2020-7770MedNov 12, 2020
    risk 0.35cvss 6.5epss 0.02

    This affects the package json8 before 1.0.3. The function adds in the target object the property specified in the path, however it does not properly check the key being set, leading to a prototype pollution.

  • CVE-2020-7643MedApr 23, 2020
    risk 0.35cvss 5.3epss 0.01

    paypal-adaptive through 0.4.2 manipulation of JavaScript objects resulting in Prototype Pollution. The PayPal function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.

  • CVE-2020-7618MedApr 7, 2020
    risk 0.35cvss 5.3epss 0.01

    sds through 3.2.0 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of the 'Object.prototype' by abusing the 'set' function located in 'js/set.js'.

  • CVE-2020-7616MedApr 7, 2020
    risk 0.35cvss 5.3epss 0.01

    express-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tricked into adding or modifying properties of the `Object.prototype`. Exploitation of this vulnerability requires creation of a new directory where an attack…

  • CVE-2018-3721MedJun 7, 2018
    risk 0.35cvss 6.5epss 0.02

    lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of…

  • CVE-2026-67319MedAug 1, 2026
    risk 0.34cvss epss 0.00

    axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript process's Object.prototype has already been polluted by another component. While the top-level merged config uses a null prototype, nested plain…

  • CVE-2026-67316MedAug 1, 2026
    risk 0.34cvss epss 0.00

    axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a separate vulnerability or dependency. In the bodyless method aliases (axios.get(), axios.delete(), axios.head(),…

  • CVE-2026-67314MedAug 1, 2026
    risk 0.34cvss epss 0.00

    axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpers/resolveConfig.js). When an application is already affected by a separate prototype-pollution primitive and makes an axios…

  • CVE-2026-55886MedJul 1, 2026
    risk 0.34cvss epss 0.00

    Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities. Versions prior to 4.12.26 are vulnerable to Prototype Pollution through Jodit.modules.Helpers.set(chain, value, obj), which walks the dot-separated chain, creating and following…

  • CVE-2026-54756MedJul 1, 2026
    risk 0.34cvss epss 0.00

    Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities. In versions prior to 4.12.18, Jodit.configure(options) — and the internal ConfigMerge / ConfigProto helpers — merged user-supplied options into the editor configuration…

  • CVE-2026-12209MedJun 15, 2026
    risk 0.34cvss 5.3epss 0.00

    A security vulnerability has been detected in RubyLouvre avalon up to 2.2.10. The impacted element is an unknown function of the file src/filters/index.js of the component Template Filter Handler. Such manipulation leads to improperly controlled modification of object prototype…

  • CVE-2026-12208MedJun 15, 2026
    risk 0.34cvss 5.3epss 0.00

    A weakness has been identified in jsonata-js jsonata up to 2.2.0. The affected element is the function createFrame of the file src/jsonata.js of the component Function Binding Frame System. This manipulation causes improperly controlled modification of object prototype…

  • CVE-2026-44292MedMay 13, 2026
    risk 0.34cvss 5.3epss 0.00

    protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated message constructors copied enumerable properties from a provided properties object without filtering the __proto__ key. If an application constructed a…

  • CVE-2026-42077MedMay 4, 2026
    risk 0.34cvss 5.2epss 0.00

    Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a prototype pollution vulnerability in the mailbox store module allows attackers to modify the behavior of all JavaScript objects by injecting malicious properties into Object.prototype. The…