VYPR

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

VariantIncomplete

Description

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-180 · CAPEC-77

CVEs mapped to this weakness (642)

page 30 of 33
  • CVE-2020-7638MedApr 6, 2020
    risk 0.28cvss 5.3epss 0.01

    confinit through 0.3.0 is vulnerable to Prototype Pollution.The 'setDeepProperty' function could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.

  • CVE-2020-7637MedApr 6, 2020
    risk 0.28cvss 5.3epss 0.01

    class-transformer before 0.3.1 allow attackers to perform Prototype Pollution. The classToPlainFromExist function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.

  • CVE-2020-7600MedMar 12, 2020
    risk 0.28cvss 5.3epss 0.01

    querymen prior to 2.1.4 allows modification of object properties. The parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. This could be abused for Prototype Pollution attacks.

  • CVE-2026-12208MedJun 15, 2026
    risk 0.27cvss 5.3epss 0.00

    A weakness has been identified in jsonata-js jsonata up to 2.2.0. The affected element is the function createFrame of the file src/jsonata.js of the component Function Binding Frame System. This manipulation causes improperly controlled modification of object prototype…

  • CVE-2026-33672MedMar 26, 2026
    risk 0.27cvss 5.3epss 0.01

    Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Because the object inherits from `Object.prototype`, specially crafted POSIX bracket…

  • CVE-2025-64718MedNov 13, 2025
    risk 0.27cvss 5.3epss 0.00

    js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse untrusted yaml documents may be impacted.…

  • CVE-2025-57353MedSep 24, 2025
    risk 0.27cvss 5.3epss 0.00

    The Runtime components of messageformat package for Node.js before 3.0.2 contain a prototype pollution vulnerability. Due to insufficient validation of nested message keys during the processing of message data, an attacker can manipulate the prototype chain of JavaScript objects…

  • CVE-2025-57352MedSep 24, 2025
    risk 0.27cvss 5.3epss 0.00

    A vulnerability exists in the 'min-document' package prior to version 2.19.0, stemming from improper handling of namespace operations in the removeAttributeNS method. By processing malicious input involving the __proto__ property, an attacker can manipulate the prototype chain…

  • CVE-2024-11628MedFeb 12, 2025
    risk 0.27cvss 4.1epss 0.01

    In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.

  • CVE-2024-12629MedFeb 12, 2025
    risk 0.27cvss 4.1epss 0.01

    In Progress® Telerik® KendoReact versions v3.5.0 through v9.4.0, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.

  • CVE-2024-54156MedDec 4, 2024
    risk 0.27cvss 4.2epss 0.00

    In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack

  • CVE-2020-7608MedMar 16, 2020
    risk 0.27cvss 5.3epss 0.01

    yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload.

  • CVE-2026-81887MedAug 31, 2026
    risk 0.26cvss —epss 0.01

    Livewire is a full-stack framework for Laravel. From 3.0.0-beta.1 until 3.8.3 and 4.3.4, the dot-notated query-string parser in js/plugins/history/index.js, including fromQueryString() and insertDotNotatedValueIntoData(), accepts the __proto__, constructor, and prototype path…

  • CVE-2026-57439MedJul 8, 2026
    risk 0.26cvss 5.0epss 0.00

    CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.2.0, the Series Chart operation accepts __proto__ as a key while parsing user-supplied CSV, allowing prototype pollution that can be chained with operations such as Parse UDP to inject…

  • CVE-2024-14020MedJan 7, 2026
    risk 0.26cvss 5.0epss 0.00

    A weakness has been identified in carboneio carbone up to fbcd349077ad0e8748be73eab2a82ea92b6f8a7e. This impacts an unknown function of the file lib/input.js of the component Formatter Handler. Executing a manipulation can lead to improperly controlled modification of object…

  • CVE-2020-7641MedJul 17, 2022
    risk 0.26cvss 4.0epss 0.00

    This affects all versions of package grunt-util-property. The function call could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.

  • CVE-2022-25862MedMay 13, 2022
    risk 0.26cvss 4.0epss 0.01

    This affects the package sds from 0.0.0. The library could be tricked into adding or modifying properties of the Object.prototype by abusing the set function located in js/set.js. **Note:** This vulnerability derives from an incomplete fix to…

  • CVE-2026-24766MedJan 28, 2026
    risk 0.25cvss 4.9epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, an authenticated user with org-level-creator permissions can exploit prototype pollution in the `/api/v2/meta/connection/test` endpoint, causing all database write operations to fail…

  • CVE-2026-59876MedJul 8, 2026
    risk 0.24cvss 4.8epss 0.00

    protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 until 8.6.5, the protobufjs Text Format extension parsed string-keyed map entries using ordinary property assignment, allowing a map entry with key __proto__ to change the prototype of the…

  • CVE-2026-44490MedJun 11, 2026
    risk 0.24cvss 4.8epss 0.00

    Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-side prototype-pollution gadgets. When Object.prototype is polluted by an upstream dependency in the same process (e.g. lodash _.merge / CVE-2018-16487), axios…