VYPR

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

VariantIncomplete

Description

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-180 · CAPEC-77

CVEs mapped to this weakness (612)

page 6 of 31
  • CVE-2024-12556HigApr 8, 2025
    risk 0.57cvss 8.7epss 0.01

    Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal.

  • CVE-2024-38988CriMar 28, 2025
    risk 0.57cvss 9.8epss 0.01

    alizeait unflatto <= 1.0.2 was discovered to contain a prototype pollution via the method exports.unflatto at /dist/index.js. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2025-25977CriMar 10, 2025
    risk 0.57cvss 9.8epss 0.01

    An issue in canvg v.4.0.2 allows an attacker to execute arbitrary code via the Constructor of the class StyleElement.

  • CVE-2024-38989CriAug 12, 2024
    risk 0.57cvss 9.8epss 0.01

    izatop bunt v0.29.19 was discovered to contain a prototype pollution via the component /esm/qs.js. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-38986CriJul 30, 2024
    risk 0.57cvss 9.8epss 0.01

    Prototype Pollution in 75lb deep-merge 1.1.1 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via merge methods of lodash to merge objects.

  • CVE-2024-38996CriJul 1, 2024
    risk 0.57cvss 9.8epss 0.01

    ag-grid-community v31.3.2 and ag-grid-enterprise v31.3.2 were discovered to contain a prototype pollution via the _.mergeDeep function. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-38992HigJul 1, 2024
    risk 0.57cvss 8.8epss 0.01

    airvertco frappejs v0.0.11 was discovered to contain a prototype pollution via the function registerView. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-38991HigJul 1, 2024
    risk 0.57cvss 8.8epss 0.01

    akbr patch-into v1.0.1 was discovered to contain a prototype pollution via the function patchInto. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-36573CriJun 17, 2024
    risk 0.57cvss 9.8epss 0.01

    almela obx before v.0.0.4 has a Prototype Pollution issue which allows arbitrary code execution via the obx/build/index.js:656), reduce (@almela/obx/build/index.js:470), Object.set (obx/build/index.js:269) component.

  • CVE-2024-24293HigMay 20, 2024
    risk 0.57cvss 8.8epss 0.01

    A Prototype Pollution issue in MiguelCastillo @bit/loader v.10.0.3 allows an attacker to execute arbitrary code via the M function e argument in index.js.

  • CVE-2024-24294CriMay 20, 2024
    risk 0.57cvss 9.8epss 0.01

    A Prototype Pollution issue in Blackprint @blackprint/engine v.0.9.0 allows an attacker to execute arbitrary code via the _utils.setDeepProperty function of engine.min.js.

  • CVE-2024-30564CriApr 18, 2024
    risk 0.57cvss 9.8epss 0.01

    An issue inandrei-tatar nora-firebase-common between v.1.0.41 and v.1.12.2 allows a remote attacker to execute arbitrary code via a crafted script to the updateState parameter of the updateStateInternal method.

  • CVE-2024-29650CriMar 25, 2024
    risk 0.57cvss 9.8epss 0.01

    An issue in @thi.ng/paths v.5.1.62 and before allows a remote attacker to execute arbitrary code via the mutIn and mutInManyUnsafe components.

  • CVE-2024-27307CriMar 6, 2024
    risk 0.57cvss 9.8epss 0.01

    JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a malicious expression can use the transform operator to override properties on the `Object` constructor and prototype. This may lead to denial of service, remote…

  • CVE-2023-46308CriJan 3, 2024
    risk 0.57cvss 9.8epss 0.01

    In Plotly plotly.js before 2.25.2, plot API calls have a risk of __proto__ being polluted in expandObjectPaths or nestedProperty.

  • CVE-2023-38894CriAug 16, 2023
    risk 0.57cvss 9.8epss 0.01

    A Prototype Pollution issue in Cronvel Tree-kit v.0.7.4 and before allows a remote attacker to execute arbitrary code via the extend function.

  • CVE-2021-26505CriAug 11, 2023
    risk 0.57cvss 9.8epss 0.01

    Prototype pollution vulnerability in MrSwitch hello.js version 1.18.6, allows remote attackers to execute arbitrary code via hello.utils.extend function.

  • CVE-2023-3696CriJul 17, 2023
    risk 0.57cvss 9.8epss 0.01

    Prototype Pollution in GitHub repository automattic/mongoose prior to 7.3.4.

  • CVE-2023-36665CriJul 5, 2023
    risk 0.57cvss 9.8epss 0.02

    "protobuf.js (aka protobufjs) 6.10.0 through 7.x before 7.2.5 allows Prototype Pollution, a different vulnerability than CVE-2022-25878. A user-controlled protobuf message can be used by an attacker to pollute the prototype of Object.prototype by adding and overwriting its data…

  • CVE-2023-36475CriJun 28, 2023
    risk 0.57cvss 9.8epss 0.03

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 5.5.2 and 6.2.1, an attacker can use a prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser. A patch is available in…