CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Parent: CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

539 vulnerabilities with CWE-1321
CVE-2026-59876 MEDIUM
protobufjs: Text Format string map parsing can mutate returned map object prototype
CVSS 4.8
CVE-2026-57439 MEDIUM
CyberChef: Prototype pollution in Series Chart operation
CVSS 5.0
CVE-2026-55886 MEDIUM
Jodit Editor: Prototype Pollution in Jodit via Jodit.modules.Helpers.set()
CVE-2026-54756 MEDIUM
Jodit Editor: Prototype pollution via Jodit.configure() / ConfigMerge
CVE-2026-57926 LOW
Jetbrains YouTrack < 2026.2.16593 - Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVSS 2.6
CVE-2026-54639 HIGH
Style Dictionary - Prototype Pollution in convertTokenData utility function
CVSS 8.8
CVE-2026-54306 MEDIUM
n8n: Prototype Pollution enables confused-deputy execution via public webhooks
CVSS 6.4
CVE-2026-44791 CRITICAL
n8n: XML Node Prototype Pollution Patch Bypass
CVSS 9.9
CVE-2026-44789 CRITICAL
n8n: HTTP Request Node Pagination Prototype Pollution to RCE
CVSS 9.9
CVE-2026-54312 HIGH
n8n: Microsoft SQL Node Prototype Pollution
CVSS 8.5
CVE-2026-55388 HIGH
piscina: Prototype Pollution Gadget → RCE via inherited options.filename
CVSS 8.1
CVE-2026-49252 CRITICAL
deepstream is vulnerable to prototype pollution
CVSS 9.9
CVE-2026-53676 HIGH
ThingsBoard - Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVSS 7.2
CVE-2026-48714 CRITICAL
i18next-http-middleware < 3.9.7 - Prototype Pollution via missingKeyHandler
CVSS 9.1
CVE-2026-48713 CRITICAL
i18next-fs-backend: Prototype pollution via crafted missing-key string
CVSS 9.1
CVE-2026-12209 MEDIUM
RubyLouvre avalon Template Filter index.js prototype pollution
CVSS 5.3
CVE-2026-12208 MEDIUM
jsonata-js jsonata Function Binding Frame System jsonata.js createFrame prototype pollution
CVSS 5.3
CVE-2026-53609 CRITICAL
Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
CVSS 9.1
CVE-2026-44495 HIGH
Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
CVSS 7.0
CVE-2026-44494 HIGH
Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
CVSS 8.7
CVE-2026-44490 MEDIUM
Axios: DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions
CVSS 4.8
CVE-2026-44489 LOW
Axios: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix
CVSS 3.7
CVE-2026-46625 HIGH
JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection
CVSS 7.5
CVE-2026-45302 HIGH
parse-nested-form-data < 1.0.1 - Prototype Pollution via FormData Field Name Traversal
CVSS 8.2
CVE-2026-46510 HIGH
Prototype pollution in form-data-objectizer via bracket-notation form keys
CVSS 8.2
Details
Vulnerabilities 539