CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Parent: CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

444 vulnerabilities with CWE-1321
CVE-2026-29063
Immutable.js <3.8.3/4.3.7/5.1.5 - Prototype Pollution
CVE-2026-28794
@orpc/client <1.13.6 - Deserialization
CVE-2026-30785
RustDesk Client - Info Disclosure
CVE-2026-27837 MEDIUM
Dottie 2.0.4-2.0.6 - Prototype Pollution
CVSS 6.3
CVE-2026-2964 MEDIUM
higuma web-audio-recorder-js 0.1/0.1.1 - Prototype Pollution
CVSS 5.0
CVE-2026-27212 HIGH
Swiper 6.5.1-12.1.1 - Prototype Pollution
CVSS 7.8
CVE-2025-70956 HIGH
TON TVM <2025.04 - Info Disclosure
CVSS 7.5
CVE-2026-26021 CRITICAL
Set-in < 2.0.5 - Prototype Pollution
CVSS 9.8
CVE-2026-25881 CRITICAL
Nyariv Sandboxjs < 0.8.31 - Prototype Pollution
CVSS 9.0
CVE-2026-25754 HIGH
Adonisjs Bodyparser < 10.1.3 - Prototype Pollution
CVSS 7.2
CVE-2026-25521 HIGH
NPM Locutus < 2.0.39 - Prototype Pollution
CVSS 8.8
CVE-2026-25150 CRITICAL
Qwik < 1.19.0 - Prototype Pollution
CVSS 9.3
CVE-2026-25142 CRITICAL
Nyariv Sandboxjs < 0.8.27 - Code Injection
CVSS 10.0
CVE-2026-25047 HIGH
NPM Deephas < 1.0.8 - Prototype Pollution
CVSS 8.8
CVE-2026-24888 MEDIUM
Microsoft Maker.js < 0.19.1 - Prototype Pollution
CVSS 6.5
CVE-2026-24766 MEDIUM
Nocodb < 0.301.0 - Prototype Pollution
CVSS 4.9
CVE-2025-61140 CRITICAL
jsonpath 1.1.1 - Info Disclosure
CVSS 9.8
CVE-2026-23736 HIGH
seroval <1.4.1 - Prototype Pollution
CVSS 7.3
CVE-2025-13465 MEDIUM
NPM Lodash < 4.17.23 - Prototype Pollution
CVSS 5.3
CVE-2026-21854 CRITICAL
Tarkov Data Manager < 2025-01-02 - Authentication Bypass
CVSS 9.8
CVE-2024-14020 MEDIUM
NPM Carbone < 3.5.6 - Code Injection
CVSS 5.0
CVE-2025-13158
NPM Apidoc-core - Prototype Pollution
CVE-2025-68130
Trpc Server < 10.45.3 - Prototype Pollution
CVE-2025-8083 HIGH
NPM Vuetify < 3.0.0-alpha.10 - Prototype Pollution
CVSS 8.6
CVE-2025-66456 CRITICAL
Elysia <1.4.16 - Prototype Pollution
CVSS 9.8
Details
Vulnerabilities 444