Prototype pollution in picomatch - CVE-2026-33672
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript code.
The method injection vulnerability affects the `POSIX_REGEX_SOURCE` object. Because the object inherits from `Object.prototype`, specially crafted POSIX bracket expressions (e.g., `[[:constructor:]]`) can reference inherited method names. These methods are implicitly converted to strings and injected into the generated regular expression. This leads to incorrect glob matching behavior (integrity impact), where patterns may match unintended filenames.. A remote attacker can pass specially crafted input to the application and perform prototype pollution, which can result in information disclosure or data manipulation.
Affected software
Optim
QRadar Threat Intelligence
QRadar Deployment Intelligence App
IBM Automation Decision Services
IBM Business Automation Workflow
IBM QRadar Data Synchronization App
How to mitigate CVE-2026-33672
Optim - update to 2.0.0
IBM Automation Decision Services - addressed in versions 24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4
IBM Business Automation Workflow - addressed in versions 24.0.0-IF009, 24.0.1-IF008, 25.0.0-IF005, 26.0.0.0
QRadar Threat Intelligence - update to 2.6.0
QRadar Deployment Intelligence App - update to 3.0.20
IBM QRadar Data Synchronization App - update to 4.0.0
External References
Related Security Bulletins
- Prototype pollution in Picomatch
- Multiple vulnerabilities in IBM QRadar Data Synchronization App
- Multiple vulnerabilities in IBM Automation Decision Services
- Multiple vulnerabilities in IBM Business Automation Workflow
- Multiple vulnerabilities in IBM Optim
- Multiple vulnerabilities in IBM QRadar Deployment Intelligence App
- Multiple vulnerabilities in IBM QRadar Threat Intelligence