PT-2026-107667 · Npm · Traverse
CVE-2026-107353
·
Published
2026-10-07
·
Updated
2026-10-07
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
traverse (npm) versions 0.3.6 through 0.3.9
traverse (npm) versions 0.4.0 through 0.4.6
traverse (npm) versions 0.5.0 through 0.5.2
traverse (npm) versions 0.6.0 through 0.6.11
Description
Prototype pollution is possible through the
set() function. When a path passed to set() crosses a primitive value, the subsequent path segment is resolved on the built-in prototype of that primitive. This allows an attacker to add or overwrite properties of String.prototype, Number.prototype, or Boolean.prototype by providing untrusted path data via plain JSON. Object.prototype can be reached using a non-data path segment, such as a Proxy or an object with a dynamic toString return value.Recommendations
Update versions 0.3.6 through 0.3.9 to 0.3.10.
Update versions 0.4.0 through 0.4.6 to 0.4.7.
Update versions 0.5.0 through 0.5.2 to 0.5.3.
Update versions 0.6.0 through 0.6.11 to 0.6.12.
As a temporary workaround, restrict the use of untrusted paths in the
set() function.Exploit
Fix
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Traverse