CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Parent: CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

539 vulnerabilities with CWE-1321
CVE-2026-14893 HIGH
IBM Instana Observability is affected by multiple Prototype Pollution within Instana Agent container image
CVSS 7.3
CVE-2026-66922 MEDIUM
Pivotick 1.4.0 - Prototype Pollution Graph Manipulation and Denial of Service
CVE-2026-65913 MEDIUM
DOMPurify before 3.3.2 Prototype Pollution via USE_PROFILES
CVSS 6.1
CVE-2026-46681 HIGH
@nevware21/ts-utils: Prototype Pollution in objDeepCopy/objCopyProps via for...in without hasOwnProperty
CVE-2026-16266 MEDIUM
Mongo-object < 3.0.3 - Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVSS 4.0
CVE-2026-53592 MEDIUM
FreeScout vulnerable to prototype pollution in getQueryParam
CVSS 4.6
CVE-2026-16151 MEDIUM
CartoDB carto-api-client filters.ts addFilter prototype pollution
CVSS 6.3
CVE-2026-16150 MEDIUM
RobinHerbots Inputmask Internal Deep Merge Helper extend.js extendAliases prototype pollution
CVSS 6.3
CVE-2026-54335 LOW
Feathersjs: Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__
CVSS 3.7
CVE-2026-48819 MEDIUM
Hey API: `buildClientParams` template: prototype chain substitution via unknown `$<slot>___proto__` key
CVSS 4.8
CVE-2026-16008 MEDIUM
sagold json-schema-library propertyDependencies.ts parsePropertyDependencies prototype pollution
CVSS 6.3
CVE-2026-45325 HIGH
Gestor de Oferta: Prototype pollution in @tmlmobilidade/utils setValueAtPath
CVSS 8.2
CVE-2026-48795 HIGH
Incomplete fix for CVE-2026-25754 in @adonisjs/bodyparser
CVSS 8.6
CVE-2026-49459 MEDIUM
DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM
CVSS 6.1
CVE-2026-15702 MEDIUM
tamagui config.ts updateConfig prototype pollution
CVSS 6.3
CVE-2026-15699 MEDIUM
spencermountain compromise Public Root API extend.js nlp.extend prototype pollution
CVSS 6.3
CVE-2026-15698 MEDIUM
kofrasa mingo Update API updateMany prototype pollution
CVSS 6.3
CVE-2026-15697 MEDIUM
svgdotjs svg.js npm Package API EventTarget.on prototype pollution
CVSS 6.3
CVE-2026-15607 MEDIUM
tanstack db Alias Path select.ts select prototype pollution
CVSS 4.3
CVE-2026-15598 MEDIUM
antv layout object.js setNestedValue prototype pollution
CVSS 6.3
CVE-2026-15538 MEDIUM
primefaces primereact API ObjectUtils.mutateFieldData prototype pollution
CVSS 6.3
CVE-2026-56763 MEDIUM
Hono - Prototype Pollution via __proto__ Key in parseBody with dot Option
CVSS 4.8
CVE-2026-15195 MEDIUM
apidevtools json-schema-ref-parser pointer.ts Pointer.set prototype pollution
CVSS 6.3
CVE-2026-59206 HIGH
n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration
CVSS 7.1
CVE-2026-15187 MEDIUM
enquirer Public Package API Enquirer.set prototype pollution
CVSS 4.3
Details
Vulnerabilities 539