PT-2026-107667 · Npm · Traverse

CVE-2026-107353

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions traverse (npm) versions 0.3.6 through 0.3.9 traverse (npm) versions 0.4.0 through 0.4.6 traverse (npm) versions 0.5.0 through 0.5.2 traverse (npm) versions 0.6.0 through 0.6.11
Description Prototype pollution is possible through the set() function. When a path passed to set() crosses a primitive value, the subsequent path segment is resolved on the built-in prototype of that primitive. This allows an attacker to add or overwrite properties of String.prototype, Number.prototype, or Boolean.prototype by providing untrusted path data via plain JSON. Object.prototype can be reached using a non-data path segment, such as a Proxy or an object with a dynamic toString return value.
Recommendations Update versions 0.3.6 through 0.3.9 to 0.3.10. Update versions 0.4.0 through 0.4.6 to 0.4.7. Update versions 0.5.0 through 0.5.2 to 0.5.3. Update versions 0.6.0 through 0.6.11 to 0.6.12. As a temporary workaround, restrict the use of untrusted paths in the set() function.

Exploit

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107353
GHSA-RJ28-8W7X-JMQC

Affected Products

Traverse