Prototype pollution in picomatch - CVE-2026-33672
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript code.
The method injection vulnerability affects the `POSIX_REGEX_SOURCE` object. Because the object inherits from `Object.prototype`, specially crafted POSIX bracket expressions (e.g., `[[:constructor:]]`) can reference inherited method names. These methods are implicitly converted to strings and injected into the generated regular expression. This leads to incorrect glob matching behavior (integrity impact), where patterns may match unintended filenames.. A remote attacker can pass specially crafted input to the application and perform prototype pollution, which can result in information disclosure or data manipulation.
Affected software
IBM QRadar Data Synchronization App
How to mitigate CVE-2026-33672
IBM QRadar Data Synchronization App - update to 4.0.0