Prototype pollution in msgpack5 - #VU152780
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to modify inherited properties of decoded objects or cause unexpected behavior in downstream code.
The vulnerability exists due to improperly controlled modification of object prototype attributes in the msgpack5 decoder when decoding a map containing a __proto__ key with an empty or partial options object. A remote attacker can supply a specially crafted map to modify the prototype of the decoded object.
Only the decoded object's prototype is affected; Object.prototype is not modified globally.