Prototype pollution in msgpack5 - #VU152780

 

Prototype pollution in msgpack5 - #VU152780

Published: September 29, 2026


Vulnerability identifier: #VU152780
CSH Severity: Medium
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-1321
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to modify inherited properties of decoded objects or cause unexpected behavior in downstream code.

The vulnerability exists due to improperly controlled modification of object prototype attributes in the msgpack5 decoder when decoding a map containing a __proto__ key with an empty or partial options object. A remote attacker can supply a specially crafted map to modify the prototype of the decoded object.

Only the decoded object's prototype is affected; Object.prototype is not modified globally.


Affected software

msgpack5

Remediation

Install security update from vendor's website.

msgpack5 - update to 6.1.0

External References

Related Security Bulletins