PT-2026-93840 · Npm · Node-Opcua-Client
CVE-2026-69200
·
Published
2026-09-16
·
Updated
2026-09-18
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
node-opcua-client versions prior to 2.145.0
Description
The
fieldsToJson() function in the packages/node-opcua-client/source/alarms and conditions/client alarm.ts file directly assigns unsanitized field names. This allows a proto .pollutedKey path to modify Object.prototype, a process known as prototype pollution where an attacker can inject properties into existing objects. This issue can lead to denial of service or corruption of application logic if an application exposes attacker-controlled event fields to the fieldsToJson() function.Recommendations
Update node-opcua-client to version 2.145.0.
Exploit
Fix
DoS
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Node-Opcua-Client