CVE-2023-26136

MEDIUM

Tough-Cookie <4.1.3 - Prototype Pollution

Title source: llm

Description

Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized.

Exploits (7)

nomisec WRITEUP 1 stars
by CUCUMBERanOrSNCompany · poc
https://github.com/CUCUMBERanOrSNCompany/SealSecurityAssignment
nomisec WORKING POC
by guy2610 · poc
https://github.com/guy2610/tough-cookie-patch-cve-2023-26136
nomisec WRITEUP
by uriyahav · poc
https://github.com/uriyahav/tough-cookie-2.5.0-cve-2023-26136-fix
nomisec WRITEUP
by morrisel · poc
https://github.com/morrisel/CVE-2023-26136
nomisec WORKING POC
by dani33339 · poc
https://github.com/dani33339/Tough-Cookie-v2.5.0-Patched
nomisec WORKING POC
by m-lito13 · poc
https://github.com/m-lito13/SealSecurity_Exam
nomisec WORKING POC
by ronmadar · poc
https://github.com/ronmadar/Open-Source-Seal-Security

Scores

CVSS v3 6.5
EPSS 0.0653
EPSS Percentile 91.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-1321
Status published
Products (2)
npm/tough-cookie 0 - 4.1.3npm
salesforce/tough-cookie < 4.1.3
Published Jul 01, 2023
Tracked Since Feb 18, 2026