Prototype Pollution in Proto
Published Sep 2, 2021
Prototype Pollution in chartkick
Published Dec 2, 2019
linux-cmdline is vulnerable to Prototype Pollution via the constructor
Published May 24, 2022
flatnest Prototype Pollution vulnerability
Published Jun 30, 2023
expr-eval vulnerable to Prototype Pollution
Published Nov 14, 2025
Prototype Pollution in dset
Published May 3, 2022
Prototype Pollution in iniparserjs
Published Apr 13, 2021
counterpart vulnerable to prototype pollution
Published Sep 24, 2025
Prototype Pollution in set-value
Published Sep 13, 2021
Prototype Pollution in bmoor
Published Feb 1, 2022
fastify: request.protocol and request.host Spoofable via X-Forwarded-Proto/Host from Untrusted Connections
Published Mar 25, 2026
Remote code execution via MongoDB BSON parser through prototype pollution
Published Nov 8, 2022
sequelize-typescript Prototype Pollution vulnerability
Published Nov 24, 2023
Parse Server vulnerable to Prototype Pollution via Cloud Code Webhooks or Cloud Code Triggers
Published Nov 9, 2022
Prototype Pollution in merge-deep
Published Jul 26, 2018
Prototype Pollution in node.extend
Published Feb 7, 2019
web3-utils Prototype Pollution vulnerability
Published Mar 27, 2024
thlorenz browserify-shim vulnerable to prototype pollution
Published Oct 31, 2022
web3-core-method is vulnerable to prototype pollution
Published Sep 24, 2025
Malicious code in @protos-team/frontend-server (npm)
Published Aug 14, 2025
Linkify Allows Prototype Pollution & HTML Attribute Injection (XSS)
Published Jul 26, 2025
Prototype Pollution in ini-parser
Published Jun 10, 2020
Prototype Pollution in set-or-get
Published Apr 12, 2021
plotly.js prototype pollution vulnerability
Published Jan 3, 2024
Resources Downloaded over Insecure Protocol in igniteui
Published Feb 18, 2019
eivindfjeldstad-dot contains prototype pollution vulnerability
Published May 25, 2021
Prototype pollution vulnerability in 'patchmerge'
Published Oct 13, 2021
radashi Allows Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Published May 27, 2025
Prototype Pollution in undefsafe
Published Feb 9, 2022
deepHas vulnerable to Prototype Pollution via constructor.prototype
Published Jan 29, 2026
Prototype Pollution in worksmith
Published May 6, 2021
Prototype pollution in nconf-toml
Published Jun 7, 2021
Prototype Pollution in lodash
Published Feb 7, 2019
Prototype pollution vulnerability in 'predefine'
Published Oct 12, 2021
Sveltejs devalue's `devalue.parse` and `devalue.unflatten` emit objects with `__proto__` own properties
Published Mar 12, 2026
Prototype Pollution in defaults-deep
Published Feb 7, 2019
Prototype Pollution in merge-options
Published Oct 9, 2018
Prototype Pollution in decal
Published Apr 13, 2021
Electron: HTTP Response Header Injection in custom protocol handlers and webRequest
Published Apr 3, 2026
json-schema-editor-visual vulnerable to prototype pollution
Published Sep 24, 2025
steal vulnerable to Prototype Pollution via requestedVersion variable
Published Sep 16, 2022
canvg Prototype Pollution vulnerability
Published Mar 10, 2025
Prototype Pollution in object-path
Published Sep 1, 2021
@ndhoule/defaults prototype pollution
Published Feb 6, 2025
Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows
Published Apr 3, 2026
Feather-Sequelize cleanQuery method vulnerable to Prototype Pollution
Published Oct 26, 2022
Prototype pollution in matrix-react-sdk
Published Mar 29, 2023
@aofl/cli-lib Prototype Pollution vulnerability
Published Jul 1, 2024
Prototype pollution in supermixer
Published Dec 10, 2021
ts-deepmerge before 2.0.2 vulnerable to Prototype Pollution
Published Aug 10, 2022
Prototype Pollution in deep.assign
Published Jul 1, 2022
Prototype pollution in multi-ini
Published Apr 13, 2021
Prototype Pollution in comb
Published Dec 16, 2021
Prototype Pollution in deep-get-set
Published May 6, 2021
Prototype Pollution in systeminformation
Published Nov 27, 2020
Prototype Pollution in express-fileupload
Published Aug 5, 2020
robinweser fast-loops vulnerable to prototype pollution
Published Jul 1, 2024
@stablelib/cbor: Prototype poisoning via `__proto__` map keys in CBOR decoding
Published Apr 4, 2026
Prototype pollution vulnerability in 'libnested'
Published Oct 12, 2021
Angular: SSRF via protocol-relative and backslash URLs in Angular Platform-Server
Published Apr 16, 2026
Locutus Prototype Pollution due to incomplete fix for CVE-2026-25521
Published Mar 27, 2026
Prototype Pollution in @strikeentco/set
Published Feb 5, 2022
Locutus has Prototype Pollution via __proto__ Key Injection in unserialize()
Published Mar 27, 2026
Prototype Pollution in handlebars
Published Feb 10, 2022
Incorrect protocol extraction via \r, \n and \t characters
Published Apr 6, 2022
Immutable is vulnerable to Prototype Pollution
Published Mar 4, 2026
Prototype Pollution in templ8
Published May 6, 2021
hoek subject to prototype pollution via the clone function.
Published Sep 25, 2022
Prototype pollution in ag-grid-community via the _.mergeDeep function
Published Jul 1, 2024
Svelte SSR attribute spreading includes inherited properties from prototype chain
Published Feb 19, 2026
Prototype Pollution
Published Sep 3, 2020
Prototype Pollution in json-ptr
Published Nov 8, 2021
Prototype Pollution in merge-change
Published Sep 1, 2021
Prototype Pollution in backbone-query-parameters
Published May 6, 2021
Prototype Pollution in merge
Published Nov 1, 2018
Prototype Pollution in open-graph
Published Sep 1, 2021
Prototype Pollution in set-value
Published Aug 27, 2019
SandboxJS Vulnerable to Prototype Pollution -> Sandbox Escape -> RCE
Published Feb 2, 2026
fast-xml-parser vulnerable to Prototype Pollution through tag or attribute name
Published Jun 13, 2023
MikroORM has Prototype Pollution in Utils.merge
Published Mar 29, 2026
dottie vulnerable to Prototype Pollution
Published Jun 10, 2023
Prototype Pollution in libnested
Published Mar 18, 2022
grunt-util-property 0.0.2 function call can add/modify properties of Object.prototype using a __proto__ payload
Published Jul 18, 2022
Prototype Pollution in litespeed.js and appwrite/server-ce
Published Feb 17, 2022
tarteaucitron.js allows prototype pollution via custom text injection
Published Apr 7, 2025
mockery is vulnerable to prototype pollution
Published Oct 12, 2022
Prototype pollution in set-object-value
Published Apr 13, 2021
jrburke requirejs vulnerable to prototype pollution
Published Jul 1, 2024
Prototype Pollution in multi-ini
Published Apr 13, 2021
dustjs-linkedin vulnerable to Prototype Pollution
Published Dec 21, 2022
Prototype Pollution in Node-Red
Published Feb 26, 2021
Prototype Pollution in mpath
Published Feb 7, 2019
Prototype Pollution in JSON5 via Parse Method
Published Dec 29, 2022
Prototype Pollution in minimist
Published Mar 18, 2022
algoliasearch-helper is vulnerable to Prototype Pollution in _merge()
Published Sep 27, 2025
Changeset vulnerable to prototype pollution
Published May 24, 2022
set-getter Prototype Pollution Vulnerability
Published Jun 21, 2021
AdonisJS multipart body parsing has Prototype Pollution issue
Published Feb 6, 2026
Prototype Pollution in vConsole
Published Apr 26, 2023
Prototype Pollution in locutus
Published May 6, 2021
Prototype Pollution in phpjs
Published May 6, 2021
seroval Affected by Prototype Pollution via JSON Deserialization
Published Jan 21, 2026
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
Published Feb 28, 2026
Prototype pollution in gsap
Published Jan 20, 2021
Arbitrary code execution in protobufjs
Published Apr 16, 2026
tree-kit Prototype Pollution vulnerability
Published Aug 17, 2023
Prototype Pollution in deep-get-set
Published Jun 25, 2022
Prototype Pollution in merge
Published May 4, 2021
OpenClaw's runtime /debug override path accepted prototype-reserved keys
Published Mar 3, 2026
Prototype Pollution in mout
Published Feb 9, 2022
Prototype Pollution in lodash
Published Jul 10, 2019
Prototype Pollution in node-oojs
Published May 6, 2021
Parse Server has Denial of Service (DoS) and Cloud Function Dispatch Bypass via Prototype Chain Resolution
Published Mar 10, 2026
web3-core-subscriptions has a Prototype Pollution vulnerability
Published Sep 24, 2025
node-cube vulnerable to prototype pollution
Published Sep 24, 2025
Prototype pollution in json8-merge-patch
Published May 10, 2021
`sveltekit-superforms` has Prototype Pollution in `parseFormData` function of `formData.js`
Published Oct 15, 2025
Prototype pollution in controlled-merge
Published May 18, 2021
Prototype Pollution in asciitable.js
Published Apr 13, 2021
Prototype Pollution in cookiex/deep
Published Sep 20, 2021
Prototype pollution in class-transformer
Published Apr 7, 2020
Prototype Pollution in set-in
Published Mar 18, 2022
Prototype pollution in json8
Published May 10, 2021
Prototype Pollution in realms-shim
Published Jan 13, 2022
Prototype Pollution in dot-notes
Published May 6, 2021
Prototype pollution in set-in
Published Mar 19, 2021
Prototype Pollution in safe-object2
Published May 6, 2021
enclave-vm Vulnerable to Sandbox Escape via Host Error Prototype Chain
Published Jan 14, 2026
Malicious code in human-protocol (npm)
Published May 18, 2025
ion-parser Prototype Pollution when malicious INI file submitted to application that parses with `parse`
Published Jul 26, 2022
Prototype pollution in Merge-deep
Published Jun 7, 2021
thlorenz browserify-shim vulnerable to prototype pollution
Published Oct 29, 2022
Prototype pollution in grpc and @grpc/grpc-js
Published May 10, 2021
tschaub gh-pages vulnerable to prototype pollution
Published Oct 12, 2022
matrix-js-sdk Prototype Pollution vulnerability
Published Mar 28, 2023
deep-object-diff vulnerable to Prototype Pollution
Published Nov 4, 2022
billboard.js allows prototype pollution via the function generate
Published Jun 4, 2025
rangy vulnerable to Prototype Pollution
Published Feb 24, 2023
Parse Server vulnerable to schema poisoning via prototype pollution in deep copy
Published Mar 17, 2026
Denial of Service in protobufjs
Published Oct 9, 2018
Prototype pollution in webpack loader-utils
Published Oct 13, 2022
Prototype Pollution in config-handler
Published Oct 12, 2021
Prototype Pollution in json-pointer
Published Nov 8, 2021
assign-deep Vulnerable to Prototype Pollution
Published Aug 21, 2019
Prototype Pollution in just-extend
Published Feb 7, 2019
Prototype Pollution in keyget
Published Feb 1, 2022
parse is vulnerable to prototype pollution
Published Sep 24, 2025
spmrc vulnerable to prototype pollution
Published Sep 24, 2025
dset vulnerable to prototype pollution
Published May 24, 2022
JSONPath vulnerable to Prototype Pollution due to insufficient input validation of object keys in lib/index.js
Published Jan 28, 2026
Prototype Pollution in Dexie
Published May 3, 2022
Prototype pollution in total.js
Published Feb 5, 2021
Prototype Pollution in property-expr
Published May 6, 2021
Prototype Pollution in Dynamoose
Published Feb 8, 2021
locutus is vulnerable to Prototype Pollution
Published Feb 2, 2026
Prototype polluation in just-safe-set
Published Dec 10, 2021
Prototype Pollution in @fabiocaccamo/utils.js
Published Dec 10, 2021
Prototype Pollution in deepmerge-ts
Published Apr 1, 2022
Prototype Pollution in decal
Published Apr 13, 2021
Malicious code in @feiprotocol/fei-protocol-core (npm)
Published Jun 20, 2022
Prototype Pollution in algoliasearch-helper
Published Nov 23, 2021
apidoc-core has a prototype pollution vulnerability
Published Dec 26, 2025
Prototype Pollution in deep-override
Published May 17, 2021
Prototype Pollution in immer
Published Jan 20, 2021
Prototype Pollution in nconf
Published Apr 13, 2022
tough-cookie Prototype Pollution vulnerability
Published Jul 1, 2023
defu: Prototype pollution via `__proto__` key in defaults argument
Published Apr 4, 2026
steal vulnerable to Prototype Pollution via alias variable
Published Sep 21, 2022
Prototype pollution in @tsed/core
Published May 10, 2021
XSS via prototype pollution in NodeBB
Published Nov 30, 2021
Duplicate Advisory: Prototype Pollution in jquery
Published Apr 23, 2019
Prototype pollution vulnerability in 'deepref'
Published Oct 12, 2021
tRPC has possible prototype pollution in `experimental_nextAppDirCaller`
Published Dec 16, 2025
Prototype Pollution in assign-deep
Published Jul 26, 2018
Prototype pollution vulnerability in 'deep-set'
Published May 24, 2022
Redoc Prototype Pollution via `Module.mergeObjects` Component
Published Mar 28, 2025
Handlebars.js has a Prototype Method Access Control Gap via Missing __lookupSetter__ Blocklist Entry
Published Mar 29, 2026
OpenAI Codex CLI enables code execution through malicious MCP (Model Context Protocol) configuration files
Published Apr 14, 2026
Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions
Published Jan 21, 2026
Prototype Pollution in js-data
Published Jan 6, 2022
Convict has Prototype Pollution via startsWith() function
Published Mar 26, 2026
angular Prototype Pollution vulnerability
Published Nov 20, 2019
thlorenz browserify-shim vulnerable to prototype pollution
Published Oct 12, 2022
Prototype Pollution in copy-props
Published Jan 6, 2022
progressbar.js vulnerable to Prototype Pollution
Published Jun 12, 2023
matrix-react-sdk Prototype pollution vulnerability
Published Mar 28, 2023
Prototype Pollution in nedb
Published Jun 21, 2021
Prototype Pollution in immer
Published Sep 2, 2021
Prototype Pollution Vulnerability in object-collider
Published Mar 19, 2021
Prototype pollution in safe-flat
Published Jun 21, 2021
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Published Feb 4, 2026
toggle-array vulnerable to prototype pollution
Published Sep 24, 2025
devalue has prototype pollution in devalue.parse and devalue.unflatten
Published Mar 12, 2026
uPlot Prototype Pollution vulnerability
Published Oct 1, 2024
Malicious code in dforce-protocol (npm)
Published Jun 20, 2022
keyget vulnerable to prototype pollution
Published May 24, 2022
Deep Merge is Vulnerable to Prototype Pollution Through Lack of Sanitization
Published Apr 20, 2026
Vuetify has a Prototype Pollution vulnerability
Published Dec 12, 2025
Prototype Pollution in Sails.js
Published Mar 18, 2022
Prototype Pollution in connie-lang
Published May 6, 2021
Prototype Pollution in node-forge
Published Sep 14, 2020
Prototype pollution in getobject
Published Oct 12, 2021
NocoDB has Prototype Pollution in Connection Test Endpoint, Leading to DoS
Published Jan 28, 2026
Parse Server vulnerable to remote code execution via MongoDB BSON parser through prototype pollution
Published Jun 30, 2023
Prototype Pollution in deephas
Published Sep 24, 2021
depath and cool-path vulnerable to Prototype Pollution via `set()` Method
Published Mar 28, 2025
Electron protocol handler browser vulnerable to Command Injection
Published Mar 26, 2018
MrSwitch hello.js vulnerable to prototype pollution
Published Aug 11, 2023
simple-git vulnerable to Remote Code Execution when enabling the ext transport protocol
Published Dec 6, 2022
Elysia Cookie Value Prototype Pollution
Published Mar 17, 2026
Unhead has XSS bypass in `useHeadSafe` via attribute name injection and case-sensitive protocol check
Published Mar 12, 2026
vue-i18n has cross-site scripting vulnerability with prototype pollution
Published Dec 2, 2024
Prototype Pollution(PP) vulnerability in setByPath
Published Nov 3, 2023
Prototype Pollution leading to Remote Code Execution in superjson
Published Feb 9, 2022
Malicious code in tellar-protocol (npm)
Published Jun 20, 2022
Parse Javascript SDK vulnerable to prototype pollution in `Parse.Object` and internal APIs
Published Oct 14, 2025
Leading white space bypasses protocol validation
Published Mar 3, 2022
mysql2 vulnerable to Prototype Poisoning
Published Apr 10, 2024
DOMPurify USE_PROFILES prototype pollution allows event handlers
Published Apr 3, 2026
node-opcua-alarm-condition prototype pollution vulnerability
Published Feb 6, 2025
Prototype Pollution in confucious
Published May 6, 2021
@stryker-mutator/util vulnerable to Prototype Pollution
Published Feb 6, 2025
Prototype Pollution in merge-recursive
Published Sep 18, 2018
Mafintosh's protocol-buffers-schema is vulnerable to prototype pollution
Published Apr 15, 2026
apidoc-core is vulnerable to prototype pollution
Published Sep 25, 2025
Prototype Pollution in simpl-schema
Published May 10, 2021
url-parse incorrectly parses hostname / protocol due to unstripped leading control characters.
Published Feb 22, 2022
Prototype Pollution in dotty
Published Nov 8, 2021
@andrei-tatar/nora-firebase-common Prototype Pollution vulnerability
Published Apr 18, 2024
@nyariv/sandboxjs has Prototype Pollution vulnerability that may lead to RCE
Published Jul 31, 2025
Prototype Pollution in madlib-object-utils
Published May 6, 2021
Prototype Pollution in putil-merge
Published Feb 5, 2022
merge vulnerable to Prototype Pollution
Published Sep 13, 2021
Prototype pollution in object-path
Published Oct 19, 2020
js-yaml has prototype pollution in merge (<<)
Published Nov 14, 2025
Prototype pollution vulnerability in js-extend
Published Jun 8, 2021
Malicious code in @ifelsedeveloper/protocol-contracts-svm-idl (npm)
Published Nov 24, 2025
Prototype Pollution in lodash
Published Jul 26, 2018
Prototype Pollution in putil-merge
Published Dec 10, 2021
Command injection in Parse Server through prototype pollution
Published Mar 11, 2022
Prototype pollution in nested-object-assign
Published Feb 1, 2021
Prototype Pollution in y18n
Published Mar 29, 2021
js-object-utilities Vulnerable to Prototype Pollution
Published Apr 7, 2025
confinit vulnerable to prototype pollution
Published Apr 7, 2020
Prototype Pollution in jointjs
Published Sep 22, 2021
magix-combine-ex vulnerable to prototype pollution
Published Sep 24, 2025
Malicious code in seatalk-protocol (npm)
Published Nov 16, 2024
Prototype Pollution in doc-path
Published May 10, 2021
mockjs vulnerable to Prototype Pollution via the Util.extend function
Published Dec 8, 2023
Prototype Pollution in the merge and clone helper methods
Published Sep 20, 2021
Prototype Pollution in nodee-utils
Published May 6, 2021
Prototype Pollution in safetydance
Published Feb 10, 2022
JSONata expression can pollute the "Object" prototype
Published Mar 4, 2024
objection.js Prototype Pollution vulnerability
Published Sep 7, 2021
estree-util-value-to-estree allows prototype pollution in generated ESTree
Published Apr 7, 2025
Prototype pollution in paypal-adaptive
Published Dec 10, 2021
set-deep-prop Prototype Pollution
Published Jul 26, 2022
automattic/mongoose vulnerable to Prototype pollution via Schema.path
Published Jul 29, 2022
Prototype pollution in object-hierarchy-access
Published Oct 12, 2021
Malicious code in web-prototyping-tool (npm)
Published Jan 14, 2025
deep-parse-json vulnerable to Prototype Pollution
Published Nov 4, 2022
Withdrawn Advisory: fast-redact vulnerable to prototype pollution
Published Sep 24, 2025
@cdr0/sg Prototype Pollution
Published Jun 17, 2024
Prototype Pollution in gammautils
Published May 6, 2021
Prototype Pollution in mixin-deep
Published Aug 27, 2019
Prototype pollution in pathval
Published Feb 10, 2022
@cat5th/key-serializer Prototype Pollution vulnerability
Published Jul 1, 2024
ts-fns has prototype pollution vulnerability
Published Sep 24, 2025
@nyariv/sandboxjs has host prototype pollution from sandbox via array intermediary (sandbox escape)
Published Feb 10, 2026
deep-defaults vulnerable to prototype pollution
Published May 24, 2022
protobufjs Prototype Pollution vulnerability
Published Jul 5, 2023
mootools-more vulnerable to prototype pollution
Published May 24, 2022
Mongoose Vulnerable to Prototype Pollution in Schema Object
Published Aug 27, 2022
Prototype Pollution in mootools
Published Sep 2, 2021
steal vulnerable to Prototype Pollution via optionName variable
Published Sep 16, 2022
Prototype Pollution in irrelon-path and @irrelon/path
Published May 6, 2021
Prototype Pollution in object-path
Published Sep 20, 2021
Parse Server is vulnerable to Prototype Pollution via Cloud Code Webhooks
Published Nov 10, 2022
Unhead has a hasDangerousProtocol() bypass via leading-zero padded HTML entities in useHeadSafe()
Published Apr 9, 2026
FurqanSoftware/node-whois vulnerable to Prototype Pollution
Published Dec 19, 2022
Prototype Pollution in simple-plist
Published Mar 23, 2022
Prototype Pollution in extend2
Published Jan 12, 2022
Prototype poisoning
Published Mar 12, 2021
expand-object Vulnerable to Prototype Pollution via the expand() Function
Published Apr 4, 2025
Mongoose Prototype Pollution vulnerability
Published Jul 17, 2023
Malicious code in @dydxprotocol/perpetual (npm)
Published Sep 23, 2022
Withdrawn: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in @xmldom/xmldom and xmldom
Published Oct 11, 2022
Malicious code in degate_protocols (npm)
Published Mar 28, 2025
@intlify/shared Prototype Pollution vulnerability
Published Dec 2, 2024
Prototype Pollution in deep-extend
Published Oct 9, 2018
Prototype Pollution in defaults-deep
Published Jul 26, 2018
CSVTOJSON has a prototype pollution vulnerability
Published Sep 24, 2025
dset Prototype Pollution vulnerability
Published Sep 11, 2024
dot-prop Prototype Pollution vulnerability
Published Jul 29, 2020
Prototype Pollution in async merge-object
Published Sep 18, 2018
Malicious code in lz-evm-protocol-v2 (npm)
Published Jul 3, 2025
LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()`
Published Apr 10, 2026
Grunt-karma vulnerable to prototype pollution
Published Oct 14, 2022
Prototype pollution in safe-obj
Published Jun 21, 2021
object-deep-assign Prototype Pollution
Published Jun 17, 2024
underscore-keypath vulnerable to Prototype Pollution
Published Aug 1, 2023
express-xss-sanitizer vulnerable to Prototype Pollution via allowedTags attribute
Published Sep 27, 2022
Malicious code in appdynamics-protobuf (npm)
Published Nov 3, 2024
Prototype pollution in nestie
Published Jun 7, 2021
Prototype Pollution in field
Published Dec 10, 2021
Baobab vulnerable to Prototype Pollution
Published Jan 7, 2023
Prototype pollution in chart.js
Published May 10, 2021
Prototype Pollution in object-path-set
Published Feb 5, 2022
Prototype Pollution in cached-path-relative
Published Nov 7, 2018
safe-eval vulnerable to Prototype Pollution via the safeEval function
Published Apr 11, 2023
@alizeait/unflatto Prototype Pollution
Published Apr 1, 2025
jquery-plugin-query-object contains prototype pollution vulnerability
Published May 24, 2022
mde utilities contains Prototype Pollution
Published Feb 28, 2023
Prototype Pollution in dot-object
Published Feb 9, 2022
Malicious code in zora1abs-protoc01-sdk (npm)
Published Jun 15, 2025
Prototype Pollution in js-data
Published Feb 9, 2022
Malicious code in mozilla-protocol (npm)
Published May 15, 2025
Malicious code in legacycloudkitresolutionserviceprotocol (npm)
Published Jun 20, 2022
n8n: Prototype Pollution in XML and GSuiteAdmin node parameters lead to RCE
Published Mar 26, 2026
jszip Vulnerable to Prototype Pollution
Published Aug 10, 2021
Prototype Pollution in lodash
Published Jul 15, 2020
Malicious code in transform-proto-to-assign (npm)
Published Mar 16, 2026
@nyariv/sandboxjs has Sandbox Escape via Prototype Whitelist Bypass and Host Prototype Pollution
Published Feb 5, 2026
ini before 1.3.6 vulnerable to Prototype Pollution via ini.parse
Published Dec 10, 2020
Prototype Pollution in extend
Published Feb 7, 2019
Prototype Pollution in nis-utils
Published May 6, 2021
module-from-string prototype pollution
Published Feb 6, 2025
Prototype pollution in dojo
Published Mar 10, 2020
Signal K Server: Arbitrary Prototype Read via `from` Field Bypass
Published Apr 3, 2026
Bun has an Application-level Prototype Pollution vulnerability in the runtime native API for Glo
Published Dec 18, 2024
Prototype Pollution in object-extend
Published Feb 19, 2022
Path traversal and code execution via prototype vulnerability
Published Jul 25, 2023
simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key enables RCE
Published Mar 10, 2026
Prototype Pollution in mixme
Published Feb 10, 2022
conf-cfg-ini Prototype Pollution via malicious INI file before v1.2.2
Published Jul 26, 2022
Prototype Pollution in ts-nodash
Published Dec 10, 2021
Prototype Pollution in deeps
Published May 6, 2021
datatables.net vulnerable to Prototype Pollution due to incomplete fix
Published Dec 17, 2020
Prototype Pollution in promisehelpers
Published May 6, 2021
dot-lens vulnerable to Prototype Pollution
Published Mar 6, 2023
Prototype Pollution in dojo
Published Jan 5, 2022
yargs-parser Vulnerable to Prototype Pollution
Published Sep 4, 2020
Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })
Published Mar 11, 2026
Malicious code in protocol-http (npm)
Published Jun 20, 2022
Prototype Pollution in highlight.js
Published Nov 24, 2020
Prototype Pollution in minimist
Published Apr 3, 2020
Prototype Pollution in arr-flatten-unflatten
Published May 6, 2021
Prototype Pollution in think-helper
Published Jul 1, 2021
Prototype Pollution in cached-path-relative
Published Jan 27, 2022
Prototype Pollution in handlebars
Published Dec 26, 2019
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
Published Dec 2, 2025
Prototype Pollution in sds
Published May 14, 2022
Prototype Pollution
Published Jun 21, 2021
csvjson vulnerable to prototype injection
Published Sep 24, 2025
dottie is vulnerable to Prototype Pollution bypass via non-first path segments in set() and transform()
Published Feb 26, 2026
rollbar vulnerable to prototype pollution
Published Oct 20, 2025
Properties-Reader before v2.2.0 vulnerable to prototype pollution
Published Jul 19, 2022
flattenizer vulnerable to prototype pollution
Published May 24, 2022
Prototype Pollution in mout
Published Jun 18, 2022
dref is vulnerable to prototype pollution
Published Sep 25, 2025
Prototype Pollution in convict
Published Apr 20, 2022
body-parser-xml vulnerable to Prototype Pollution
Published Sep 14, 2021
Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection
Published Mar 26, 2026
OpenClaw: Sandbox browser CDP relay could expose DevTools protocol on 0.0.0.0
Published Apr 17, 2026
Parse Server's Cloud function dispatch crashes server via prototype chain traversal
Published Mar 17, 2026
Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
Published Feb 9, 2026
Prototype Pollution in x-assign
Published Oct 21, 2021
CASL Ability is Vulnerable to Prototype Pollution
Published Feb 10, 2026
Prototype pollution in aurelia-path
Published Sep 27, 2021
Prototype Pollution in Dojox
Published Mar 10, 2020
sassdoc-extras vulnerable to prototype pollution
Published Sep 24, 2025
Prototype Pollution in mixin-deep
Published Jul 26, 2018
@ianwalter/merge Prototype Pollution via `merge` function
Published Jul 26, 2022
Prototype pollution not blocked by object-path related utilities in hoolock
Published Jan 23, 2024
DOMPurify allows tampering by prototype pollution
Published Sep 16, 2024
json-schema-ref-parser Prototype Pollution issue
Published May 20, 2024
Collection.js vulnerable to Prototype Pollution
Published Mar 18, 2023
tree-kit vulnerable to Prototype Pollution
Published Dec 25, 2022
Angular is Vulnerable to XSRF Token Leakage via Protocol-Relative URLs in Angular HTTP Client
Published Nov 26, 2025
Malicious code in mw-proto-models (npm)
Published Jan 20, 2026
ReDoS in Sec-Websocket-Protocol header
Published May 28, 2021
component-flatten vulnerable to Prototype Pollution
Published May 24, 2022
Malicious code in @cashcowprotocol/keccak-crypto (npm)
Published May 19, 2025
Prototype Pollution in record-like-deep-assign
Published Dec 10, 2021
Apollo Federation vulnerable to prototype pollution via incomplete key sanitization
Published Mar 13, 2026
Malicious code in teller-protocol (npm)
Published Jun 20, 2022
steal vulnerable to Prototype Pollution
Published Sep 17, 2022
Prototype pollution in json-pointer
Published May 10, 2021
Prototype pollution in dotty
Published Feb 5, 2021
Prototype Pollution in merge-deep2.
Published Dec 16, 2021
Malicious code in proton-super-package (npm)
Published Jun 20, 2022
Malicious code in com.henryhoffman.unlockprotocol (npm)
Published Apr 3, 2025
devalue `uneval`ed code can create objects with polluted prototypes when `eval`ed
Published Feb 19, 2026
Vega vulnerable to Cross-site Scripting via RegExp.prototype[@@replace]
Published Mar 27, 2025
`@orpc/client` has Prototype Pollution via `StandardRPCJsonSerializer` Deserialization
Published Mar 2, 2026
Prototype Pollution in querymen
Published Jun 18, 2022
Prototype Pollution in jsgui-lang-essentials
Published May 3, 2022
fastest-json-copy vulnerable to Prototype Pollution
Published Nov 4, 2022
Prototype Pollution in protobufjs
Published May 28, 2022
Prototype Pollution Protection Bypass in qs
Published Apr 30, 2020
Prototype Pollution in bmoor
Published May 10, 2021
Prototype pollution in izatop bunt
Published Aug 12, 2024
Prototype pollution in swiper
Published Feb 19, 2026
Prototype Pollution in gedi
Published May 6, 2021
Prototype Pollution in convict
Published May 14, 2022
Prototype Pollution in realms-shim
Published Jan 12, 2022
Malicious code in @dydxprotocol/solo (npm)
Published Sep 23, 2022
shvl vulnerable to prototype pollution
Published May 24, 2022
NodeBB vulnerable to account takeover via prototype vulnerability
Published Dec 5, 2022
Prototype Pollution via parse() in NodeJS flatted
Published Mar 19, 2026
min-document vulnerable to prototype pollution
Published Sep 24, 2025
Prototype pollution in JointJS
Published Jan 20, 2021
Prototype Pollution in swiper
Published May 10, 2021
npm package rfc6902 vulnerable to Prototype Pollution
Published Dec 15, 2022
Prototype Pollution in lutils
Published Jun 21, 2021
Prototype Pollution in tiny-conf
Published May 10, 2021
Prototype Pollution in NASA Open MCT
Published Oct 6, 2023
Malicious code in compound-protocol (npm)
Published Jan 28, 2025
Malicious code in eslint-config-proton-lint (npm)
Published Jan 5, 2025
Prototype Pollution via file load in aws-sdk and @aws-sdk/shared-ini-file-loader
Published Nov 16, 2021
Prototype Pollution in madlib-object-utils
Published Apr 16, 2022
Malicious code in google-protobuf-conformance (npm)
Published Jul 24, 2025
steal vulnerable to Prototype Pollution via key variable in babel.js
Published Sep 16, 2022
Prototype Pollution in bodymen
Published Mar 18, 2022
vxe-table prototype pollution
Published Feb 6, 2025
Next.js is vulnerable to RCE in React flight protocol
Published Dec 3, 2025
Prototype Pollution in sds
Published Sep 3, 2020
Prototype Pollution in vm2
Published Oct 19, 2021
LiquidJS: ownPropertyOnly bypass via sort_natural filter — prototype property information disclosure through sorting side-channel
Published Apr 8, 2026
Prototype pollution in matrix-js-sdk (part 2)
Published Mar 30, 2023
antfu/utils vulnerable to prototype pollution
Published May 30, 2023
Malicious code in @asyncapi/protobuf-schema-parser (npm)
Published Nov 24, 2025
TypeORM vulnerable to MAID and Prototype Pollution
Published May 7, 2021
Prototype Pollution in sey
Published Dec 16, 2021
mysql2 vulnerable to Prototype Pollution
Published May 30, 2024
NocoBase Affected by Sandbox Escape to RCE via console._stdout Prototype Chain Traversal in Workflow Script Node
Published Mar 30, 2026
Prototype Pollution in mathjs
Published May 10, 2021
Prototype Pollution in handlebars
Published Jun 5, 2019
matrix-js-sdk subject to user spoofing via Olm/Megolm protocol confusion
Published Sep 30, 2022
Protocol-Relative URL Injection via Single Backslash Bypass in Angular SSR
Published Mar 19, 2026
Prototype Pollution in deepmergefn
Published Aug 10, 2021
Prototype pollution in @strikeentco/set
Published May 24, 2022
messageformat has a prototype pollution vulnerability
Published Sep 24, 2025
Malicious code in @protos-team/frontend-platform (npm)
Published Aug 14, 2025
Malicious code in @protos-team/frontend-primitives (npm)
Published Aug 14, 2025
Malicious code in matic-protocol (npm)
Published Jun 20, 2022
Malicious code in com.google.devtools.atsconsole.controller.proto (npm)
Published May 9, 2023
Malicious code in skfb-viewer-protocol (npm)
Published Jun 20, 2022
Malicious code in yandex-yt-proto (npm)
Published Jan 30, 2023
Malicious code in @tickertape/protos-pbjs (npm)
Published Jul 8, 2022
Malicious code in @protonme/routing (npm)
Published Feb 24, 2026
Malicious code in relay-prototyping-tools (npm)
Published Mar 11, 2025
Malicious code in limitd-protocol (npm)
Published Sep 11, 2023
Malicious code in omniprotocol (npm)
Published Jun 1, 2022
Malicious code in protobufjs-databricks (npm)
Published Jun 20, 2022
Malicious code in protons-benchmark (npm)
Published Jul 29, 2022
Prototype Pollution in deeply
Published Aug 27, 2019
Possible prototype pollution in metadata record, when using meta decorator
Published May 1, 2023
Malicious code in fei-protocol-core (npm)
Published Jun 20, 2022
Malicious code in @proto-services/banking (npm)
Published Jul 21, 2022
Prototype pollution in Plist before 3.0.5 can cause denial of service
Published Feb 18, 2022
Malicious code in protobufjs-shopee (npm)
Published Nov 27, 2024
Malicious code in proton-vpn-browser-extension (npm)
Published Nov 27, 2024
Malicious code in rlending-protocol (npm)
Published Nov 27, 2024
H3 has an Open Redirect via Protocol-Relative Path in redirectBack() Referer Validation
Published Mar 23, 2026
Malicious code in proton-parking-page (npm)
Published Dec 27, 2024
Malicious code in mw-proto-ts (npm)
Published Dec 11, 2025
Malicious code in sui-lending-protocol (npm)
Published Mar 18, 2025
Prototype Pollution in node-jsonpointer
Published Nov 8, 2021
set-in Affected by Prototype Pollution
Published Feb 11, 2026
Evolver has Prototype Pollution via `Object.assign()` in its mailbox store operations
Published Apr 22, 2026
flat vulnerable to Prototype Pollution
Published Dec 25, 2022
Prototype pollution in min-dash
Published Feb 1, 2022
Malicious code in @proto-services/integration (npm)
Published Jul 21, 2022
ag-grid packages vulnerable to Prototype Pollution
Published Jul 1, 2024
i18next-http-middleware: Prototype pollution and path traversal via user-controlled language and namespace parameters
Published Apr 22, 2026
Malicious code in zora1abs-protoc-helper (npm)
Published Jun 15, 2025
SAP HANA Node.js client package vulnerable to Prototype Pollution
Published Oct 8, 2024
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`
Published Apr 1, 2026
Convict has prototype pollution via load(), loadFile(), and schema initialization
Published Mar 26, 2026
Elysia vulnerable to prototype pollution with multiple standalone schema validation
Published Dec 9, 2025
DOMPurify: Prototype Pollution to XSS Bypass via CUSTOM_ELEMENT_HANDLING Fallback
Published Apr 22, 2026
Prototype Pollution in fullpage.js
Published Apr 12, 2022
Prototype Pollution in handlebars
Published Sep 4, 2020
Prototype Pollution via FormData Processing in Qwik City
Published Feb 3, 2026
parse-server has cloud function validator bypass via prototype chain traversal
Published Mar 31, 2026
Haraka affected by DoS via `__proto__` email header
Published Apr 1, 2026
mpregular vulnerable to prototype pollution
Published Sep 24, 2025
Malicious code in @protos-team/frontend-utils (npm)
Published Aug 14, 2025
Malicious code in protonme (npm)
Published May 25, 2024
Malicious code in hover-design-prototype (npm)
Published Nov 24, 2025
Malicious code in compound-protocol-alpha (npm)
Published Jan 28, 2025