PT-2026-56483 · Cyberchef · Cyberchef
CVSS v3.1
5.0
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
CyberChef versions prior to 11.2.0
Description
The Series Chart operation allows prototype pollution when parsing user-supplied CSV data because it accepts
proto as a key. Prototype pollution is a technique where an attacker manipulates the prototype of an object to change the behavior of the application. This flaw can be combined with other operations, such as Parse UDP, to inject malicious JavaScript into the HTML output.Recommendations
Update to version 11.2.0.
Exploit
Fix
XSS
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cyberchef