VYPR

CWE-915

Improperly Controlled Modification of Dynamically-Determined Object Attributes

BaseIncomplete

Description

The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (230)

page 6 of 12
  • CVE-2022-48359HigMar 27, 2023
    risk 0.49cvss 7.5epss 0.00

    The recovery mode for updates has a vulnerability that causes arbitrary disk modification. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2021-23442HigSep 17, 2021
    risk 0.49cvss 8.6epss 0.02

    This affects all versions of package @cookiex/deep. The global proto object can be polluted using the __proto__ object.

  • CVE-2021-32736HigJun 30, 2021
    risk 0.49cvss 7.5epss 0.01

    think-helper defines a set of helper functions for ThinkJS. In versions of think-helper prior to 1.1.3, the software receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control…

  • CVE-2026-49428HigAug 19, 2026
    risk 0.48cvss 8.4epss 0.00

    Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly free memory in largepage objects. These operations are not permitted on largepage objects, but the implementation did not verify this. An unprivileged local user can abuse the bug…

  • CVE-2026-45687HigJun 24, 2026
    risk 0.48cvss 8.5epss 0.00

    Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's sendFileMessage DDP method passes the entire attacker-supplied file object into Uploads.updateFileComplete,…

  • CVE-2026-39942HigApr 9, 2026
    risk 0.48cvss 8.5epss 0.00

    Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id} endpoint accepts a user-controlled filename_disk parameter. By setting this value to match the storage path of another user's file, an attacker can overwrite…

  • CVE-2021-23402HigJul 2, 2021
    risk 0.48cvss 7.3epss 0.01

    All versions of package record-like-deep-assign are vulnerable to Prototype Pollution via the main functionality.

  • CVE-2020-7679HigJun 19, 2020
    risk 0.48cvss 7.3epss 0.02

    In all versions of package casperjs, the mergeObjects utility function is susceptible to Prototype Pollution.

  • CVE-2026-61591HigSep 16, 2026
    risk 0.46cvss 8.1epss 0.00

    djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restored on reconnect as trusted view state…

  • CVE-2026-47849HigAug 27, 2026
    risk 0.46cvss 7.1epss 0.00

    Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+json) requests. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - 4.5.12 Spring Data REST 4.0.0 -…

  • CVE-2026-77144HigAug 25, 2026
    risk 0.46cvss —epss 0.00

    The frontend management plugin attributed a newly created event to the submitting user's organizer record only when the request supplied no organizer of its own. The accompanying permission check confirmed only that the submitting user held any organizer role. A user with…

  • CVE-2026-71504HigAug 24, 2026
    risk 0.46cvss 8.1epss 0.00

    Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of any user account, including the system administrator, without verifying password-change permissions.…

  • CVE-2026-42863HigJun 8, 2026
    risk 0.46cvss 8.1epss 0.00

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the chatflow update endpoint of FlowiseAI. The endpoint allows clients to modify server-controlled properties such as…

  • CVE-2026-22814HigJan 13, 2026
    risk 0.46cvss —epss 0.01

    @adonisjs/lucid is an SQL ORM for AdonisJS built on top of Knex. Prior to 21.8.2 and 22.0.0-next.6, there is a Mass Assignment vulnerability in AdonisJS Lucid which may allow a remote attacker who can influence data that is passed into Lucid model assignments to overwrite the…

  • CVE-2025-61781HigJan 5, 2026
    risk 0.46cvss 7.1epss 0.00

    OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.1, the GraphQL mutation "WorkspacePopoverDeletionMutation" allows users to delete workspace-related objects such as dashboards and investigation cases.…

  • CVE-2025-30358HigMar 27, 2025
    risk 0.46cvss 8.1epss 0.01

    Mesop is a Python-based UI framework that allows users to build web applications. A class pollution vulnerability in Mesop prior to version 0.14.1 allows attackers to overwrite global variables and class attributes in certain Mesop modules during runtime. This vulnerability…

  • CVE-2022-43441HigMar 16, 2023
    risk 0.46cvss 8.1epss 0.02

    A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1. A specially-crafted Javascript file can lead to arbitrary code execution. An attacker can provide malicious input to trigger this vulnerability.

  • CVE-2022-24802HigApr 1, 2022
    risk 0.46cvss 8.1epss 0.02

    deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. deepmerge-ts is vulnerable to Prototype Pollution via file deepmerge.ts, function defaultMergeRecords(). This issue has been patched in version 4.0.2. There are no known…

  • CVE-2020-7774HigNov 17, 2020
    risk 0.46cvss 7.3epss 0.69

    The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.

  • CVE-2026-46721MedMay 19, 2026
    risk 0.45cvss —epss 0.00

    The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignment. As a result, an attacker can assign an arbitrary frontend user group to a newly registered or edited account, gaining…