VYPR

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

VariantIncomplete

Description

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-180 · CAPEC-77

CVEs mapped to this weakness (642)

page 29 of 33
  • CVE-2020-28460MedDec 22, 2020
    risk 0.30cvss 5.6epss 0.02

    This affects the package multi-ini before 2.1.2. It is possible to pollute an object's prototype by specifying the constructor.proto object as part of an array. This is a bypass of CVE-2020-28448.

  • CVE-2020-7748MedOct 20, 2020
    risk 0.30cvss 5.6epss 0.02

    This affects the package @tsed/core before 5.65.7. This vulnerability relates to the deepExtend function which is used as part of the utils directory. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program.

  • CVE-2020-15366MedJul 15, 2020
    risk 0.30cvss 5.6epss 0.02

    An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code by prototype pollution. (While untrusted schemas are recommended against, the worst case of an…

  • CVE-2020-7598MedMar 11, 2020
    risk 0.30cvss 5.6epss 0.02

    minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.

  • CVE-2026-73647MedAug 13, 2026
    risk 0.29cvss 5.6epss 0.00

    Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the public extend() utility in ui/src/utils/extend/extend.js recursively copied attacker-controlled object keys during extend(true, target, source) deep merges without…

  • CVE-2026-40190MedApr 10, 2026
    risk 0.29cvss 5.6epss 0.00

    LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScript/TypeScript SDK (langsmith) contains an incomplete prototype pollution fix in its internally vendored lodash set() utility. The baseAssignValue() function…

  • CVE-2025-31475MedApr 7, 2025
    risk 0.29cvss 5.5epss 0.00

    tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where the addOrUpdate function, used for applying custom texts, did not properly validate input. This allowed an attacker with direct access to the…

  • CVE-2021-4278MedDec 25, 2022
    risk 0.29cvss 5.5epss 0.00

    A vulnerability classified as problematic has been found in cronvel tree-kit up to 0.6.x. This affects an unknown part. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). Upgrading to version 0.7.0 is able to…

  • CVE-2021-4245MedDec 15, 2022
    risk 0.29cvss 5.5epss 0.01

    A vulnerability classified as problematic has been found in chbrown rfc6902. This affects an unknown part of the file pointer.ts. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The exploit has been disclosed…

  • CVE-2020-7617MedApr 2, 2020
    risk 0.29cvss 4.4epss 0.01

    ini-parser through 0.0.2 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of Object.prototype using a '__proto__' payload.

  • CVE-2026-70610MedAug 5, 2026
    risk 0.28cvss 5.4epss 0.01

    Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.4, objects copied across the contextBridge boundary from untrusted content could carry an attacker-influenced prototype,…

  • CVE-2026-15187MedJul 9, 2026
    risk 0.28cvss 4.3epss 0.00

    A security flaw has been discovered in enquirer up to 2.4.1. Affected is the function Enquirer.set of the component Public Package API. The manipulation of the argument question.name results in improperly controlled modification of object prototype attributes. The attack can be…

  • CVE-2026-9101MedMay 20, 2026
    risk 0.28cvss 4.3epss 0.00

    Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering shell.openExternal after specific user behavior leading to "1-click" command execution.

  • CVE-2025-13465MedJan 21, 2026
    risk 0.28cvss 5.3epss 0.02

    Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow…

  • CVE-2025-3982MedApr 27, 2025
    risk 0.28cvss 4.3epss 0.01

    A vulnerability, which was classified as problematic, was found in nortikin Sverchok 1.3.0. Affected is the function SvSetPropNodeMK2 of the file sverchok/nodes/object_nodes/getsetprop_mk2.py of the component Set Property Mk2 Node. The manipulation leads to improperly controlled…

  • CVE-2024-45277MedOct 8, 2024
    risk 0.28cvss 4.3epss 0.01

    The SAP HANA Node.js client package versions from 2.0.0 before 2.21.31 is impacted by Prototype Pollution vulnerability allowing an attacker to add arbitrary properties to global object prototypes. This is due to improper user input sanitation when using the nestTables feature…

  • CVE-2023-0842MedApr 5, 2023
    risk 0.28cvss 5.3epss 0.01

    xml2js version 0.4.23 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the __proto__ property to be edited.

  • CVE-2022-41713MedNov 3, 2022
    risk 0.28cvss 5.3epss 0.01

    deep-object-diff version 1.1.0 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the '__proto__' property to be edited.

  • CVE-2021-23413MedJul 25, 2021
    risk 0.28cvss 5.3epss 0.03

    This affects the package jszip before 3.7.0. Crafting a new zip file with filenames set to Object prototype values (e.g __proto__, toString, etc) results in a returned object with a modified prototype instance.

  • CVE-2020-7639MedApr 6, 2020
    risk 0.28cvss 5.3epss 0.01

    eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.