VYPR

Vaadin Charts

by Vaadin

CVEs (1)

  • CVE-2026-91860MedSep 30, 2026
    risk 0.34cvss —epss —

    A prototype pollution vulnerability exists in the deep merge helpers of Vaadin Charts and Vaadin Component Base. Merging an object the application does not control into a chart configuration or into a component's i18n property writes onto Object.prototype, making the injected…