VYPR

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

VariantIncomplete

Description

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-180 · CAPEC-77

CVEs mapped to this weakness (612)

page 27 of 31
  • CVE-2021-23807MedNov 3, 2021
    risk 0.30cvss 5.6epss 0.03

    This affects the package jsonpointer before 5.0.0. A type confusion vulnerability can lead to a bypass of a previous Prototype Pollution fix when the pointer components are arrays.

  • CVE-2021-23509MedNov 3, 2021
    risk 0.30cvss 5.6epss 0.02

    This affects the package json-ptr before 3.0.0. A type confusion vulnerability can lead to a bypass of CVE-2020-7766 when the user-provided keys used in the pointer parameter are arrays.

  • CVE-2021-23444MedSep 21, 2021
    risk 0.30cvss 5.6epss 0.02

    This affects the package jointjs before 3.4.2. A type confusion vulnerability can lead to a bypass of CVE-2020-28480 when the user-provided keys used in the path parameter are arrays in the setByPath function.

  • CVE-2021-23436MedSep 1, 2021
    risk 0.30cvss 5.6epss 0.02

    This affects the package immer before 9.0.6. A type confusion vulnerability can lead to a bypass of CVE-2020-28477 when the user-provided keys used in the path parameter are arrays. In particular, this bypass is possible because the condition (p === "__proto__" || p ===…

  • CVE-2021-23434MedAug 27, 2021
    risk 0.30cvss 5.6epss 0.02

    This affects the package object-path before 0.11.6. A type confusion vulnerability can lead to a bypass of CVE-2020-15256 when the path components used in the path parameter are arrays. In particular, the condition currentPath === '__proto__' returns false if currentPath is…

  • CVE-2021-23383MedMay 4, 2021
    risk 0.30cvss 5.6epss 0.05

    The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.

  • CVE-2020-28460MedDec 22, 2020
    risk 0.30cvss 5.6epss 0.02

    This affects the package multi-ini before 2.1.2. It is possible to pollute an object's prototype by specifying the constructor.proto object as part of an array. This is a bypass of CVE-2020-28448.

  • CVE-2020-7748MedOct 20, 2020
    risk 0.30cvss 5.6epss 0.02

    This affects the package @tsed/core before 5.65.7. This vulnerability relates to the deepExtend function which is used as part of the utils directory. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program.

  • CVE-2020-15366MedJul 15, 2020
    risk 0.30cvss 5.6epss 0.02

    An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code by prototype pollution. (While untrusted schemas are recommended against, the worst case of an…

  • CVE-2020-7598MedMar 11, 2020
    risk 0.30cvss 5.6epss 0.02

    minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.

  • CVE-2026-73647MedAug 13, 2026
    risk 0.29cvss 5.6epss 0.00

    Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the public extend() utility in ui/src/utils/extend/extend.js recursively copied attacker-controlled object keys during extend(true, target, source) deep merges without…

  • CVE-2026-40190MedApr 10, 2026
    risk 0.29cvss 5.6epss 0.00

    LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScript/TypeScript SDK (langsmith) contains an incomplete prototype pollution fix in its internally vendored lodash set() utility. The baseAssignValue() function…

  • CVE-2025-31475MedApr 7, 2025
    risk 0.29cvss 5.5epss 0.00

    tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where the addOrUpdate function, used for applying custom texts, did not properly validate input. This allowed an attacker with direct access to the…

  • CVE-2021-4278MedDec 25, 2022
    risk 0.29cvss 5.5epss 0.00

    A vulnerability classified as problematic has been found in cronvel tree-kit up to 0.6.x. This affects an unknown part. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). Upgrading to version 0.7.0 is able to…

  • CVE-2021-4245MedDec 15, 2022
    risk 0.29cvss 5.5epss 0.01

    A vulnerability classified as problematic has been found in chbrown rfc6902. This affects an unknown part of the file pointer.ts. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The exploit has been disclosed…

  • CVE-2021-23624MedNov 3, 2021
    risk 0.29cvss 5.6epss 0.01

    This affects the package dotty before 0.1.2. A type confusion vulnerability can lead to a bypass of CVE-2021-25912 when the user-provided keys used in the path parameter are arrays.

  • CVE-2020-7617MedApr 2, 2020
    risk 0.29cvss 4.4epss 0.01

    ini-parser through 0.0.2 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of Object.prototype using a '__proto__' payload.

  • CVE-2026-70610MedAug 5, 2026
    risk 0.28cvss 5.4epss 0.00

    Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.4, objects copied across the contextBridge boundary from untrusted content could carry an attacker-influenced prototype,…

  • CVE-2026-15187MedJul 9, 2026
    risk 0.28cvss 4.3epss 0.00

    A security flaw has been discovered in enquirer up to 2.4.1. Affected is the function Enquirer.set of the component Public Package API. The manipulation of the argument question.name results in improperly controlled modification of object prototype attributes. The attack can be…

  • CVE-2026-9101MedMay 20, 2026
    risk 0.28cvss 4.3epss 0.00

    Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering shell.openExternal after specific user behavior leading to "1-click" command execution.