CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Parent: CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

539 vulnerabilities with CWE-1321
CVE-2026-46509 HIGH
deepobj: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVSS 8.2
CVE-2026-44483 HIGH
RVF: Prototype pollution in @rvf/set-get reachable via @rvf/core preprocessFormData (HTTP form data)
CVSS 8.2
CVE-2026-44966 HIGH
Velocity.js: Prototype Pollution in #set path assignment
CVSS 8.3
CVE-2026-9101 MEDIUM
MongoDB Compass - Prototype Pollution via CSV Import Leading to Command Execution
CVSS 4.3
CVE-2026-8657 HIGH
Jsondiffpatch < 0.7.6 - Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVSS 8.2
CVE-2026-44005 CRITICAL
vm2: Sandbox escape
CVSS 10.0
CVE-2026-44292 MEDIUM
protobufjs: Prototype injection in generated message constructors
CVSS 5.3
CVE-2026-44290 HIGH
protobufjs: Process-wide denial of service through unsafe option paths
CVSS 7.5
CVE-2026-8161 HIGH
multiparty vulnerable to Denial of Service via Prototype Pollution leading to Uncaught Exception
CVSS 7.5
CVE-2026-41690 HIGH
Prototype pollution and path traversal in i18next-http-middleware via user-controlled language and namespace parameters
CVSS 8.6
CVE-2026-42264 HIGH
Axios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection and request hijacking
CVSS 7.4
CVE-2026-42232 HIGH
n8n: XML Node Prototype Pollution to RCE
CVSS 8.8
CVE-2026-42231 HIGH
n8n: Prototype Pollution in XML Webhook Body Parser Leads to RCE
CVSS 8.8
CVE-2026-42077 MEDIUM
Evolver: Prototype Pollution via `Object.assign()` in mailbox store operations
CVSS 5.2
CVE-2026-42044 MEDIUM
Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
CVSS 6.5
CVE-2026-42041 MEDIUM
Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
CVSS 4.8
CVE-2026-42035 HIGH
Axios: Header Injection via Prototype Pollution
CVSS 7.4
CVE-2026-42033 HIGH
Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
CVSS 7.4
CVE-2026-41238 MEDIUM
DOMPurify: Prototype Pollution to XSS Bypass via CUSTOM_ELEMENT_HANDLING Fallback
CVSS 6.9
CVE-2026-6621 HIGH
1024bit extend-deep index.js prototype pollution
CVSS 7.3
CVE-2026-6594 HIGH
brikcss merge prototype pollution
CVSS 7.3
CVE-2026-34626 MEDIUM
Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
CVSS 6.3
CVE-2026-34622 HIGH
Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
CVSS 8.6
CVE-2026-34621 HIGH KEV
Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
CVSS 8.6
CVE-2026-40190 MEDIUM
LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()`
CVSS 5.6
Details
Vulnerabilities 539