PT-2026-56483 · Cyberchef · Cyberchef

·

CVE-2026-57439

·

Published

2026-07-08

·

Updated

2026-07-10

CVSS v3.1

5.0

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CyberChef versions prior to 11.2.0
Description The Series Chart operation allows prototype pollution when parsing user-supplied CSV data because it accepts proto as a key. Prototype pollution is a technique where an attacker manipulates the prototype of an object to change the behavior of the application. This flaw can be combined with other operations, such as Parse UDP, to inject malicious JavaScript into the HTML output.
Recommendations Update to version 11.2.0.

Exploit

Fix

XSS

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57439
GHSA-FX6F-382R-J72C

Affected Products

Cyberchef