CVE-2026-107353

Source
https://cve.org/CVERecord?id=CVE-2026-107353
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107353.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107353
Aliases
  • GHSA-rj28-8w7x-jmqc
Downstream
Published
2026-10-07T19:35:15Z
Modified
2026-10-09T02:49:21Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
traverse: set() can write to built-in prototypes via an untrusted path
Details

traverse (npm) versions 0.3.6 through 0.3.9, 0.4.0 through 0.4.6, 0.5.0 through 0.5.2, and 0.6.0 through 0.6.11 allow prototype pollution through set(). When the path passed to set() crosses a primitive value, the next path segment is resolved on that primitive's built-in prototype, so an application that passes an untrusted path to set() lets an attacker add or overwrite properties of String.prototype, Number.prototype, or Boolean.prototype using plain JSON data, for example traverse({ name: 'bob' }).set(['name', 'proto', 'polluted'], 'yes'). Object.prototype was reachable only with a non-data path segment, such as an object whose toString returns a different value on each call, or through a Proxy that accepts an assignment without storing it. This is fixed in 0.3.10, 0.4.7, 0.5.3, and 0.6.12.

Database specific
{
    "cna_assigner": "harborist",
    "cwe_ids": [
        "CWE-1321"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107353.json"
}
References

Affected packages

Git / github.com/ljharb/js-traverse

Affected ranges

Type
GIT
Repo
https://github.com/ljharb/js-traverse
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.3.6"
        },
        {
            "fixed": "0.3.10"
        },
        {
            "introduced": "0.4.0"
        },
        {
            "fixed": "0.4.7"
        },
        {
            "introduced": "0.5.0"
        },
        {
            "fixed": "0.5.3"
        },
        {
            "introduced": "0.6.0"
        },
        {
            "fixed": "0.6.12"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v0.*
v0.3.6
v0.3.7
v0.3.8
v0.3.9
v0.4.0
v0.4.1
v0.4.2
v0.4.3
v0.4.4
v0.4.5
v0.4.6
v0.5.0
v0.5.1
v0.5.2
v0.6.0
v0.6.1
v0.6.10
v0.6.11
v0.6.2
v0.6.3
v0.6.4
v0.6.5
v0.6.6
v0.6.7
v0.6.8
v0.6.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107353.json"