PT-2026-98344 · Software Mansion · React Native Worklets

CVE-2026-97724

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Software Mansion React Native Worklets versions prior to 0.12.2
Description Prototype pollution occurs when an attacker-controlled object containing a proto property modifies the prototype of an object created during serialization within the clonePlainJSObject() function. This issue can lead to a remotely triggered denial of service, causing the React Native application to crash when the malformed serialized object is processed. If the attacker-controlled data is persisted, the denial of service may persist across application restarts or repeated attempts to access the affected content.
Recommendations Update to version 0.12.2 or later.

Exploit

Fix

DoS

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97724

Affected Products

React Native Worklets