Ridwan Arefin Islam

Researcher fromMadiba Security Lab, Concordia University
#46302of 57,635
6.3Total CVSS
Vulnerabilities · 1
PT-2026-103274
6.3
2026-09-30
Vaadin · @Vaadin/Charts · CVE-2026-91860
**Name of the Vulnerable Software and Affected Versions** Vaadin versions 23.0.0 through 23.6.13 Vaadin versions 24.0.0 through 24.9.20 Vaadin versions 24.10.0 through 24.10.9 Vaadin versions 25.0.0 through 25.1.11 Vaadin versions 25.2.0 through 25.2.6 com.vaadin:vaadin-core versions 24.7.0 through 24.9.20 com.vaadin:vaadin-core versions 24.10.0 through 24.10.9 com.vaadin:vaadin-core versions 25.0.0 through 25.1.11 com.vaadin:vaadin-core versions 25.2.0 through 25.2.6 com.vaadin:vaadin-charts-flow versions 23.0.0 through 23.6.13 com.vaadin:vaadin-charts-flow versions 24.0.0 through 24.9.20 com.vaadin:vaadin-charts-flow versions 24.10.0 through 24.10.9 com.vaadin:vaadin-charts-flow versions 25.0.0 through 25.1.11 com.vaadin:vaadin-charts-flow versions 25.2.0 through 25.2.6 @vaadin/charts versions 23.0.0 through 23.6.4 @vaadin/charts versions 24.0.0 through 24.9.17 @vaadin/charts versions 24.10.0 through 24.10.4 @vaadin/charts versions 25.0.0 through 25.1.11 @vaadin/charts versions 25.2.0 through 25.2.8 @vaadin/component-base versions 24.7.0 through 24.9.17 @vaadin/component-base versions 24.10.0 through 24.10.4 @vaadin/component-base versions 25.0.0 through 25.1.11 @vaadin/component-base versions 25.2.0 through 25.2.8 **Description** A prototype pollution issue exists in the deep merge helpers of Vaadin Charts and Vaadin Component Base. This occurs when an object not controlled by the application is merged into a chart configuration or a component's `i18n` property. This action writes to `Object.prototype`, which makes the injected properties accessible to every object within the running application. Prototype pollution is a technique where an attacker manipulates the prototype of a base object to inject properties that can change the behavior of the application. **Recommendations** Upgrade Vaadin versions 23.0.0 through 23.6.13 to 23.6.14 Upgrade Vaadin versions 24.0.0 through 24.9.20 to 24.9.21 Upgrade Vaadin versions 24.10.0 through 24.10.9 to 24.10.10 Upgrade Vaadin versions 25.0.0 through 25.1.11 to 25.1.12 Upgrade Vaadin versions 25.2.0 through 25.2.6 to 25.2.7 or newer Upgrade com.vaadin:vaadin-core versions 24.7.0 through 24.9.20 to 24.9.21 Upgrade com.vaadin:vaadin-core versions 24.10.0 through 24.10.9 to 24.10.10 Upgrade com.vaadin:vaadin-core versions 25.0.0 through 25.1.11 to 25.1.12 Upgrade com.vaadin:vaadin-core versions 25.2.0 through 25.2.6 to 25.2.7 Upgrade com.vaadin:vaadin-charts-flow versions 23.0.0 through 23.6.13 to 23.6.14 Upgrade com.vaadin:vaadin-charts-flow versions 24.0.0 through 24.9.20 to 24.9.21 Upgrade com.vaadin:vaadin-charts-flow versions 24.10.0 through 24.10.9 to 24.10.10 Upgrade com.vaadin:vaadin-charts-flow versions 25.0.0 through 25.1.11 to 25.1.12 Upgrade com.vaadin:vaadin-charts-flow versions 25.2.0 through 25.2.6 to 25.2.7 Upgrade @vaadin/charts versions 23.0.0 through 23.6.4 to 23.6.5 Upgrade @vaadin/charts versions 24.0.0 through 24.9.17 to 24.9.18 Upgrade @vaadin/charts versions 24.10.0 through 24.10.4 to 24.10.5 Upgrade @vaadin/charts versions 25.0.0 through 25.1.11 to 25.1.12 Upgrade @vaadin/charts versions 25.2.0 through 25.2.8 to 25.2.9 Upgrade @vaadin/component-base versions 24.7.0 through 24.9.17 to 24.9.18 Upgrade @vaadin/component-base versions 24.10.0 through 24.10.4 to 24.10.5 Upgrade @vaadin/component-base versions 25.0.0 through 25.1.11 to 25.1.12 Upgrade @vaadin/component-base versions 25.2.0 through 25.2.8 to 25.2.9