CVE-2026-107301

Source
https://cve.org/CVERecord?id=CVE-2026-107301
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107301.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107301
Aliases
Published
2026-10-08T17:13:00Z
Modified
2026-10-09T02:49:21Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L CVSS Calculator
Summary
msgpack5: Partial options disable prototype protection
Details

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, constructing msgpack5 with an empty or partial options object disables the default protoAction: 'error' protection. A decoded map containing a proto key can then replace the decoded object's prototype, potentially changing inherited properties or downstream behavior, although Object.prototype is not modified globally. This issue is fixed in version 6.1.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-1321"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107301.json"
}
References

Affected packages

Git / github.com/mcollina/msgpack5

Affected ranges

Type
GIT
Repo
https://github.com/mcollina/msgpack5
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "6.1.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v1.*
v1.2.0
v1.3.1
v1.3.2
v1.5.0
v1.6.0
v2.*
v2.0.0
v2.1.0
v2.2.0
v2.3.0
v2.3.1
v3.*
v3.0.0
v3.1.0
v3.2.0
v3.3.0
v3.4.0
v3.4.1
v3.5.0
v3.6.0
v3.6.1
v4.*
v4.0.0
v4.0.1
v4.0.2
v4.1.0
v4.2.0
v4.3.0
v4.4.0
v5.*
v5.0.0
v5.1.0
v5.2.0
v5.2.1
v5.3.0
v5.3.1
v5.3.2
v6.*
v6.0.0
v6.0.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107301.json"