PT-2026-107184 · Npm · @Stablelib/Cbor

CVE-2026-106448

·

Published

2026-04-04

·

Updated

2026-10-06

CVSS v4.0

8.9

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions @stablelib/cbor versions prior to 2.0.4
Description The CBOR map decoding path creates ordinary JavaScript objects and assigns attacker-controlled keys using bracket assignment. When a map key named proto is used, it invokes the inherited prototype setter rather than creating a standard own property. This allows the prototype of the decoded object to be populated with attacker-controlled values, such as authorization or feature-flag settings. Consequently, downstream code that relies on normal property lookup or merges the decoded object may make security-sensitive decisions based on this inherited data.
Recommendations Update to version 2.0.4.

Exploit

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106448
GHSA-W48F-FWG7-WW6P

Affected Products

@Stablelib/Cbor