VYPR

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

VariantIncomplete

Description

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-180 · CAPEC-77

CVEs mapped to this weakness (612)

page 26 of 31
  • CVE-2026-27837MedFeb 26, 2026
    risk 0.34cvss 6.3epss 0.00

    Dottie provides nested object access and manipulation in JavaScript. Versions 2.0.4 through 2.0.6 contain an incomplete fix for CVE-2023-26132. The prototype pollution guard introduced in commit `7d3aee1` only validates the first segment of a dot-separated path, allowing an…

  • CVE-2024-39001MedJul 1, 2024
    risk 0.34cvss 6.3epss 0.01

    ag-grid-enterprise v31.3.2 was discovered to contain a prototype pollution via the component _ModuleSupport.jsonApply. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-2495MedMar 15, 2024
    risk 0.34cvss 5.2epss 0.00

    Cryptographic key vulnerability encoded in the FriendlyWrt firmware affecting version 2022-11-16.51b3d35. This vulnerability could allow an attacker to compromise the confidentiality and integrity of encrypted data.

  • CVE-2024-23339MedJan 22, 2024
    risk 0.34cvss 6.3epss 0.01

    hoolock is a suite of lightweight utilities designed to maintain a small footprint when bundled. Starting in version 2.0.0 and prior to version 2.2.1, utility functions related to object paths (`get`, `set`, and `update`) did not block attempts to access or alter object…

  • CVE-2021-4307MedJan 7, 2023
    risk 0.34cvss 6.3epss 0.01

    A vulnerability was found in Yomguithereal Baobab up to 2.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The…

  • CVE-2022-4742MedDec 26, 2022
    risk 0.34cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, has been found in json-pointer up to 0.6.1. Affected by this issue is the function set of the file index.js. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution').…

  • CVE-2021-4279MedDec 25, 2022
    risk 0.34cvss 6.3epss 0.01

    A vulnerability has been found in Starcounter-Jack JSON-Patch up to 3.1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The attack can…

  • CVE-2020-36632MedDec 25, 2022
    risk 0.34cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, was found in hughsk flat up to 5.0.0. This affects the function unflatten of the file index.js. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). It is possible…

  • CVE-2021-4264MedDec 21, 2022
    risk 0.34cvss 6.3epss 0.01

    A vulnerability was found in LinkedIn dustjs up to 2.x and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The attack may be…

  • CVE-2020-36618MedDec 19, 2022
    risk 0.34cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in Furqan node-whois. Affected is an unknown function of the file index.coffee. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). It is possible to launch the…

  • CVE-2022-42743MedNov 3, 2022
    risk 0.34cvss 5.3epss 0.01

    deep-parse-json version 1.0.2 allows an external attacker to edit or add new properties to an object. This is possible because the application does not correctly validate the incoming JSON keys, thus allowing the '__proto__' property to be edited.

  • CVE-2022-41714MedNov 3, 2022
    risk 0.34cvss 5.3epss 0.01

    fastest-json-copy version 1.0.1 allows an external attacker to edit or add new properties to an object. This is possible because the application does not correctly validate the incoming JSON keys, thus allowing the '__proto__' property to be edited.

  • CVE-2026-65913MedJul 23, 2026
    risk 0.33cvss 6.1epss 0.00

    DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute filtering by polluting Array.prototype properties. Attackers can set Array.prototype properties like onclick to true, causing DOMPurify to accept…

  • CVE-2026-49459MedJul 14, 2026
    risk 0.33cvss 6.1epss 0.00

    DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attributes on an attacker-controlled root when a descendant name clobbered properties checked by…

  • CVE-2026-2964MedFeb 23, 2026
    risk 0.33cvss 5.0epss 0.00

    A vulnerability was identified in higuma web-audio-recorder-js 0.1/0.1.1. Impacted is the function extend in the library lib/WebAudioRecorder.js of the component Dynamic Config Handling. Such manipulation leads to improperly controlled modification of object prototype…

  • CVE-2025-53626MedJul 10, 2025
    risk 0.33cvss 6.1epss 0.00

    pdfme is a TypeScript-based PDF generator and React-based UI. The expression evaluation feature in pdfme 5.2.0 to 5.4.0 contains critical vulnerabilities allowing sandbox escape leading to XSS and prototype pollution attacks. This vulnerability is fixed in 5.4.1.

  • CVE-2025-62517MedOct 23, 2025
    risk 0.31cvss 5.9epss 0.00

    Rollbar.js offers error tracking and logging from Javascript to Rollbar. In versions before 2.26.5 and from 3.0.0-alpha1 to before 3.0.0-beta5, there is a prototype pollution vulnerability in merge(). If application code calls rollbar.configure() with untrusted input, prototype…

  • CVE-2024-34273MedMay 16, 2024
    risk 0.31cvss 5.9epss 0.00

    njwt up to v0.4.0 was discovered to contain a prototype pollution in the Parser.prototype.parse method.

  • CVE-2021-23433MedNov 19, 2021
    risk 0.31cvss 5.9epss 0.02

    The package algoliasearch-helper before 3.6.2 are vulnerable to Prototype Pollution due to use of the merge function in src/SearchParameters/index.jsSearchParameters._parseNumbers without any protection against prototype properties. Note that this vulnerability is only…

  • CVE-2021-23820MedNov 3, 2021
    risk 0.30cvss 5.6epss 0.02

    This affects all versions of package json-pointer. A type confusion vulnerability can lead to a bypass of CVE-2020-7709 when the pointer components are arrays.