CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
539 vulnerabilities with CWE-1321
CVE-2026-14893
HIGH
IBM Instana Observability is affected by multiple Prototype Pollution within Instana Agent container image
CVSS 7.3
CVE-2026-66922
MEDIUM
Pivotick 1.4.0 - Prototype Pollution Graph Manipulation and Denial of Service
CVE-2026-65913
MEDIUM
DOMPurify before 3.3.2 Prototype Pollution via USE_PROFILES
CVSS 6.1
CVE-2026-46681
HIGH
@nevware21/ts-utils: Prototype Pollution in objDeepCopy/objCopyProps via for...in without hasOwnProperty
CVE-2026-16266
MEDIUM
Mongo-object < 3.0.3 - Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVSS 4.0
CVE-2026-53592
MEDIUM
FreeScout vulnerable to prototype pollution in getQueryParam
CVSS 4.6
CVE-2026-16151
MEDIUM
CartoDB carto-api-client filters.ts addFilter prototype pollution
CVSS 6.3
CVE-2026-16150
MEDIUM
RobinHerbots Inputmask Internal Deep Merge Helper extend.js extendAliases prototype pollution
CVSS 6.3
CVE-2026-54335
LOW
Feathersjs: Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__
CVSS 3.7
CVE-2026-48819
MEDIUM
Hey API: `buildClientParams` template: prototype chain substitution via unknown `$<slot>___proto__` key
CVSS 4.8
CVE-2026-16008
MEDIUM
sagold json-schema-library propertyDependencies.ts parsePropertyDependencies prototype pollution
CVSS 6.3
CVE-2026-45325
HIGH
Gestor de Oferta: Prototype pollution in @tmlmobilidade/utils setValueAtPath
CVSS 8.2
CVE-2026-48795
HIGH
Incomplete fix for CVE-2026-25754 in @adonisjs/bodyparser
CVSS 8.6
CVE-2026-49459
MEDIUM
DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM
CVSS 6.1
CVE-2026-15702
MEDIUM
tamagui config.ts updateConfig prototype pollution
CVSS 6.3
CVE-2026-15699
MEDIUM
spencermountain compromise Public Root API extend.js nlp.extend prototype pollution
CVSS 6.3
CVE-2026-15698
MEDIUM
kofrasa mingo Update API updateMany prototype pollution
CVSS 6.3
CVE-2026-15697
MEDIUM
svgdotjs svg.js npm Package API EventTarget.on prototype pollution
CVSS 6.3
CVE-2026-15607
MEDIUM
tanstack db Alias Path select.ts select prototype pollution
CVSS 4.3
CVE-2026-15598
MEDIUM
antv layout object.js setNestedValue prototype pollution
CVSS 6.3
CVE-2026-15538
MEDIUM
primefaces primereact API ObjectUtils.mutateFieldData prototype pollution
CVSS 6.3
CVE-2026-56763
MEDIUM
Hono - Prototype Pollution via __proto__ Key in parseBody with dot Option
CVSS 4.8
CVE-2026-15195
MEDIUM
apidevtools json-schema-ref-parser pointer.ts Pointer.set prototype pollution
CVSS 6.3
CVE-2026-59206
HIGH
n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration
CVSS 7.1
CVE-2026-15187
MEDIUM
enquirer Public Package API Enquirer.set prototype pollution
CVSS 4.3
Details
Vulnerabilities
539