PT-2026-97326 · Npm · Scim-Patch

CVE-2026-61834

·

Published

2026-09-23

·

Updated

2026-09-28

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions scim-patch versions prior to 0.9.2
Description The library fails to properly validate SCIM PATCH paths, allowing the navigate() function to read inherited properties and the assign() function to use prototype-chain membership checks. An attacker can use a path or dotted value keys starting with an inherited property, such as toString, to traverse into a shared built-in function object and inject attacker-controlled properties. This leads to process-global mutation, which can compromise application logic that relies on inherited-method properties.
Recommendations Update to version 0.9.2.

Exploit

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61834
GHSA-2MHW-WCX5-V3XJ

Affected Products

Scim-Patch