CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Parent: CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

473 vulnerabilities with CWE-1321
CVE-2025-68130 HIGH
Trpc Server < 10.45.3 - Prototype Pollution
CVE-2025-8083 HIGH
NPM Vuetify < 3.0.0-alpha.10 - Prototype Pollution
CVSS 8.6
CVE-2025-66456 CRITICAL
Elysia <1.4.16 - Prototype Pollution
CVSS 9.8
CVE-2025-13204 HIGH
Silentmatt Javascript Expression Evaluator - Prototype Pollution
CVSS 7.3
CVE-2025-64718 MEDIUM
Nodeca Js-yaml < 3.14.2 - Prototype Pollution
CVSS 5.3
CVE-2025-62517 MEDIUM
NPM Rollbar < 2.26.5 - Prototype Pollution
CVSS 5.9
CVE-2025-62410 CRITICAL
NPM Happy-dom < 20.0.2 - Prototype Pollution
CVE-2025-62381 HIGH
NPM Sveltekit-superforms < 2.27.4 - Prototype Pollution
CVE-2025-62374 MEDIUM
NPM Parse < 7.0.0 - Prototype Pollution
CVSS 6.4
CVE-2025-3193 HIGH
Algoliasearch-helper < 3.11.2 - Prototype Pollution
CVSS 7.5
CVE-2025-26278 HIGH
NPM Dref - Prototype Pollution
CVSS 7.5
CVE-2025-57324 MEDIUM
Parseplatform Parse Javascript SDK < 5.3.0 - Prototype Pollution
CVSS 6.5
CVE-2025-57320 MEDIUM
Open-federation Json-schema-editor-visual - Prototype Pollution
CVSS 6.5
CVE-2025-57318 HIGH
Pradeep-mishra Csvjson < 5.1.0 - Prototype Pollution
CVSS 7.5
CVE-2025-57329 HIGH
Web3js Web3-core-method < 1.10.4 - Prototype Pollution
CVSS 7.5
CVE-2025-57328 HIGH
Jonschlinkert Toggle-array < 1.0.1 - Prototype Pollution
CVSS 7.5
CVE-2025-57327 HIGH
Spmjs Spmrc < 1.2.0 - Prototype Pollution
CVSS 7.5
CVE-2025-57326 HIGH
Sassdoc-extras < 2.5.1 - Prototype Pollution
CVSS 7.5
CVE-2025-57325 HIGH
Rollbar < 2.26.4 - Prototype Pollution
CVSS 7.5
CVE-2025-57323 HIGH
Regularjs Mpregular < 0.2.0 - Prototype Pollution
CVSS 7.5
CVE-2025-57321 CRITICAL
Magix-combine-ex < 1.2.10 - Prototype Pollution
CVSS 9.8
CVE-2025-57351 MEDIUM
NPM Ts-fns - Prototype Pollution
CVSS 6.5
CVE-2025-57349 HIGH
Openjsf Messageformat < 2.3.0 - Prototype Pollution
CVSS 7.5
CVE-2025-57348 MEDIUM
Node-cube < 5.0.0 - Prototype Pollution
CVSS 6.5
CVE-2025-57347 CRITICAL
Tbo47 Dagre-d3-es - Prototype Pollution
CVSS 9.8
Details
Vulnerabilities 473