CVE-2026-57439
MEDIUMCyberChef: Prototype pollution in Series Chart operation
Title source: cnaDescription
CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.2.0, the Series Chart operation accepts __proto__ as a key while parsing user-supplied CSV, allowing prototype pollution that can be chained with operations such as Parse UDP to inject malicious JavaScript into HTML output. This issue is fixed in version 11.2.0.
References (5)
Core 5
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/gchq/CyberChef/security/advisories/GHSA-fx6f-382r-j72c
X_Refsource_Misc x_refsource_misc
https://github.com/gchq/CyberChef/issues/2568
X_Refsource_Misc x_refsource_misc
https://github.com/gchq/CyberChef/pull/2569
X_Refsource_Misc x_refsource_misc
https://github.com/gchq/CyberChef/commit/85db3be5d0096859b810f0e8d3e151d5dc9b948f
X_Refsource_Misc x_refsource_misc
https://github.com/gchq/CyberChef/releases/tag/v11.2.0
Scores
CVSS v3
5.0
EPSS
0.0009
EPSS Percentile
0.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1321
CWE-79
Status
published
Products (1)
gchq/CyberChef
< 11.2.0
Published
Jul 08, 2026
Tracked Since
Jul 08, 2026