VYPR

CWE-915

Improperly Controlled Modification of Dynamically-Determined Object Attributes

BaseIncomplete

Description

The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (230)

page 9 of 12
  • CVE-2021-23421MedAug 11, 2021
    risk 0.36cvss 5.6epss 0.01

    All versions of package merge-change are vulnerable to Prototype Pollution via the utils.set function.

  • CVE-2021-23417MedJul 28, 2021
    risk 0.36cvss 5.6epss 0.01

    All versions of package deepmergefn are vulnerable to Prototype Pollution via deepMerge function.

  • CVE-2026-63102MedJul 20, 2026
    risk 0.35cvss 5.4epss 0.00

    rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role field through the Users API during user creation or profile updates. Attackers can exploit the…

  • CVE-2026-59888MedJul 14, 2026
    risk 0.35cvss 6.5epss 0.00

    jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnor…

  • CVE-2026-42044MedApr 24, 2026
    risk 0.35cvss 6.5epss 0.01

    Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into surgical,…

  • CVE-2026-21886MedMar 17, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.9.1, the GraphQL mutations "IndividualDeletionDeleteMutation" is intended to allow users to delete individual entity objects respectively. However, it was…

  • CVE-2026-28781MedMar 4, 2026
    risk 0.35cvss 6.5epss 0.00

    Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the entry creation process allows for Mass Assignment of the authorId attribute. A user with "Create Entries" permission can inject the authorIds[] (or authorId) parameter into the POST request,…

  • CVE-2025-70559MedFeb 3, 2026
    risk 0.35cvss 6.5epss 0.00

    pdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The library uses Python pickle to deserialize CMap cache files without validation. An attacker with the ability to place a malicious pickle file in a location…

  • CVE-2020-7618MedApr 7, 2020
    risk 0.35cvss 5.3epss 0.01

    sds through 3.2.0 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of the 'Object.prototype' by abusing the 'set' function located in 'js/set.js'.

  • CVE-2020-7616MedApr 7, 2020
    risk 0.35cvss 5.3epss 0.01

    express-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tricked into adding or modifying properties of the `Object.prototype`. Exploitation of this vulnerability requires creation of a new directory where an attack…

  • CVE-2026-17598MedAug 7, 2026
    risk 0.34cvss —epss 0.00

    Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when creating or updating a scheduled task through the administrative UI. An account holding permission to create at least one scheduled task type could supply a…

  • CVE-2026-55223MedJun 30, 2026
    risk 0.34cvss —epss 0.00

    c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination with other libraries, can compose to a "sink" for deserialization gadgets. The JDBC spec's DataSource.getConnection() and ConnectionPoolDataSource.getPooledConnection() match the…

  • CVE-2023-39983MedSep 2, 2023
    risk 0.34cvss 5.3epss 0.01

    A vulnerability that poses a potential risk of polluting the MXsecurity sqlite database and the nsm-web UI has been identified in MXsecurity versions prior to v1.0.1. This vulnerability might allow an unauthenticated remote attacker to register or add devices via the nsm-web…

  • CVE-2026-78038MedAug 30, 2026
    risk 0.31cvss —epss 0.00

    Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the :args option of AshOban.build_trigger/3 to retarget an update or destroy trigger at another record, including across…

  • CVE-2026-55736MedJun 23, 2026
    risk 0.31cvss —epss 0.00

    Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument that is intended to be controlled only by trusted server-side code. Action arguments declared with…

  • CVE-2022-4068MedNov 20, 2022
    risk 0.31cvss 5.4epss 0.36

    A user is able to enable their own account if it was disabled by an admin while the user still holds a valid session. Moreover, the username is not properly sanitized in the admin user overview. This enables an XSS attack that enables an attacker with a low privilege user to…

  • CVE-2021-23433MedNov 19, 2021
    risk 0.31cvss 5.9epss 0.02

    The package algoliasearch-helper before 3.6.2 are vulnerable to Prototype Pollution due to use of the merge function in src/SearchParameters/index.jsSearchParameters._parseNumbers without any protection against prototype properties. Note that this vulnerability is only…

  • CVE-2026-31252MedMay 11, 2026
    risk 0.30cvss 5.7epss 0.00

    CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its model loading component. The framework uses torch.load() to load model weight files (e.g., llm.pt, flow.pt, hift.pt) without enabling…

  • CVE-2020-7748MedOct 20, 2020
    risk 0.30cvss 5.6epss 0.02

    This affects the package @tsed/core before 5.65.7. This vulnerability relates to the deepExtend function which is used as part of the utils directory. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program.

  • CVE-2020-15366MedJul 15, 2020
    risk 0.30cvss 5.6epss 0.02

    An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code by prototype pollution. (While untrusted schemas are recommended against, the worst case of an…