CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
539 vulnerabilities with CWE-1321
CVE-2026-59876
MEDIUM
protobufjs: Text Format string map parsing can mutate returned map object prototype
CVSS 4.8
CVE-2026-57439
MEDIUM
CyberChef: Prototype pollution in Series Chart operation
CVSS 5.0
CVE-2026-55886
MEDIUM
Jodit Editor: Prototype Pollution in Jodit via Jodit.modules.Helpers.set()
CVE-2026-54756
MEDIUM
Jodit Editor: Prototype pollution via Jodit.configure() / ConfigMerge
CVE-2026-57926
LOW
Jetbrains YouTrack < 2026.2.16593 - Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVSS 2.6
CVE-2026-54639
HIGH
Style Dictionary - Prototype Pollution in convertTokenData utility function
CVSS 8.8
CVE-2026-54306
MEDIUM
n8n: Prototype Pollution enables confused-deputy execution via public webhooks
CVSS 6.4
CVE-2026-44791
CRITICAL
n8n: XML Node Prototype Pollution Patch Bypass
CVSS 9.9
CVE-2026-44789
CRITICAL
n8n: HTTP Request Node Pagination Prototype Pollution to RCE
CVSS 9.9
CVE-2026-54312
HIGH
n8n: Microsoft SQL Node Prototype Pollution
CVSS 8.5
CVE-2026-55388
HIGH
piscina: Prototype Pollution Gadget → RCE via inherited options.filename
CVSS 8.1
CVE-2026-49252
CRITICAL
deepstream is vulnerable to prototype pollution
CVSS 9.9
CVE-2026-53676
HIGH
ThingsBoard - Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVSS 7.2
CVE-2026-48714
CRITICAL
i18next-http-middleware < 3.9.7 - Prototype Pollution via missingKeyHandler
CVSS 9.1
CVE-2026-48713
CRITICAL
i18next-fs-backend: Prototype pollution via crafted missing-key string
CVSS 9.1
CVE-2026-12209
MEDIUM
RubyLouvre avalon Template Filter index.js prototype pollution
CVSS 5.3
CVE-2026-12208
MEDIUM
jsonata-js jsonata Function Binding Frame System jsonata.js createFrame prototype pollution
CVSS 5.3
CVE-2026-53609
CRITICAL
Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
CVSS 9.1
CVE-2026-44495
HIGH
Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
CVSS 7.0
CVE-2026-44494
HIGH
Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
CVSS 8.7
CVE-2026-44490
MEDIUM
Axios: DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions
CVSS 4.8
CVE-2026-44489
LOW
Axios: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix
CVSS 3.7
CVE-2026-46625
HIGH
JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection
CVSS 7.5
CVE-2026-45302
HIGH
parse-nested-form-data < 1.0.1 - Prototype Pollution via FormData Field Name Traversal
CVSS 8.2
CVE-2026-46510
HIGH
Prototype pollution in form-data-objectizer via bracket-notation form keys
CVSS 8.2
Details
Vulnerabilities
539