Passing an empty or partial options object disables the default protoAction: 'error' protection. A map containing a __proto__ key can then replace the prototype of the decoded object, potentially changing inherited properties or causing unexpected behavior in downstream code.
Only the decoded object's prototype is affected; this does not modify Object.prototype globally.
Options are now merged with secure defaults without modifying the caller's object. Unsupported protoAction values are rejected.
Explicitly set protoAction: 'error' whenever constructing a msgpack5 instance, and validate decoded values before use.
{
"cwe_ids": [
"CWE-1321"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-08T17:39:57Z",
"nvd_published_at": null,
"severity": "MODERATE"
}