PT-2026-108061 · Mcollina+1 · Msgpack5

CVE-2026-107301

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions msgpack5 versions prior to 6.1.0
Description Constructing the software with an empty or partial options object disables the default protoAction: 'error' protection. This allows a decoded map containing a proto key to replace the prototype of the decoded object, which can change inherited properties or cause unexpected behavior in downstream code. This issue affects only the decoded object's prototype and does not modify Object.prototype globally.
Recommendations Update to version 6.1.0. Explicitly set protoAction: 'error' when constructing a msgpack5 instance. Validate decoded values before use.

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107301
GHSA-8HQ7-GGX2-CC6M

Affected Products

Msgpack5