top of page
perceptive_background_267k.jpg

parse-nested-form-data is a tiny node module for parsing FormData by name into objects and arrays. Prior to version 1.0.1, parseFormData() walks bracket and dot…

Published:

31 mei 2026 om 22:00:00

Alert date:

1 juni 2026 om 20:04:42

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Web Technologies

A prototype pollution vulnerability in the parse-nested-form-data Node.js module allows attackers to pollute Object.prototype by crafting FormData field names containing __proto__. The parseFormData() function fails to filter reserved property keys when processing bracket and dot-notation field names. This enables traversal onto Object.prototype and assignment of properties there, affecting all plain objects in the running process. The vulnerability was patched in version 1.0.1 of the module.

Technical details

Mitigation steps:

Affected products:

parse-nested-form-data

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page