CWE-915

Improperly Controlled Modification of Dynamically-Determined Object Attributes

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.

138 vulnerabilities with CWE-915
CVE-2026-55736 MEDIUM
Ash 3.0.0 to < 3.29.3 - Private Action Argument Injection
CVE-2026-56276 MEDIUM
Flowise - Mass Assignment in PUT /api/v1/user Allows Password Hash Override
CVE-2026-56142 CRITICAL
Jetbrains Hub - Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVSS 9.9
CVE-2026-44495 HIGH
Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
CVSS 7.0
CVE-2026-44494 HIGH
Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
CVSS 8.7
CVE-2026-46625 HIGH
JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection
CVSS 7.5
CVE-2026-46517 HIGH
LMDeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out
CVSS 7.8
CVE-2026-46480 HIGH
Flowise: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover
CVSS 8.8
CVE-2026-46479 HIGH
Flowise: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover
CVSS 8.8
CVE-2026-46478 HIGH
Flowise: DatasetRow create+update mass-assignment allows cross-workspace row takeover
CVSS 8.8
CVE-2026-46477 HIGH
Flowise: Dataset create+update mass-assignment allows cross-workspace dataset takeover
CVSS 8.8
CVE-2026-46476 HIGH
Flowise: CustomTemplate create+update mass-assignment allows cross-workspace template takeover
CVSS 8.8
CVE-2026-46475 HIGH
Flowise: Assistant create+update mass-assignment allows cross-workspace assistant takeover
CVSS 8.8
CVE-2026-46441 CRITICAL
Flowise: Mass Assignment in Assistant Update Endpoint Allows Cross-Workspace Resource Reassignment
CVSS 9.6
CVE-2026-42863 HIGH
Flowise: Mass Assignment in Chatflow Update Endpoint Allows Cross-Workspace AgentFlow Reassignment
CVSS 8.1
CVE-2026-42862 MEDIUM
Flowise: Mass Assignment in Tool Update Endpoint Allows Cross-Workspace Resource Reassignment
CVSS 5.0
CVE-2026-42861 CRITICAL
Flowise: Mass Assignment in Variable Update Endpoint Allows Cross-Workspace Resource Reassignment
CVSS 9.6
CVE-2026-42540 MEDIUM
IRIS <2.4.28 - Mass Assignment
CVSS 4.3
CVE-2026-45058 CRITICAL
electerm: Import unsafe bookmark data could lead to unsafe operation when click local type bookmark
CVE-2026-44635 HIGH
Kysely: JSON-path traversal injection via unsanitized path-leg metacharacters in `JSONPathBuilder.key()` / `.at()`
CVSS 7.5
CVE-2026-48150 CRITICAL
Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
CVSS 9.0
CVE-2026-8327 MEDIUM
Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass.
CVSS 4.3
CVE-2026-47102 HIGH
LiteLLM < 1.83.10 Privilege Escalation via User Update
CVSS 8.8
CVE-2026-6366 MEDIUM
Drupal core - Moderately critical - Gadget Chain - SA-CORE-2026-002
CVSS 6.6
CVE-2026-46721 MEDIUM
Broken Access Control in extension "Frontend User Registration" (sf_register)
Details
Vulnerabilities 138