


Perceptive Security
SOC/SIEM Consultancy

deepobj provides get, set, delete deep objects in javascript. Prior to 1.0.3, prototype pollution is possible when property paths contain __proto__/constructor/…
Published:
27 mei 2026 om 22:00:00
Alert date:
28 mei 2026 om 20:05:25
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
The deepobj JavaScript library, which provides functionality to get, set, and delete deep objects, contains a prototype pollution vulnerability prior to version 1.0.3. The vulnerability occurs when property paths contain __proto__/constructor/prototype elements. Exploitation requires that property paths are exposed as user input. The issue has been resolved in version 1.0.3 of the library.
Technical details
Mitigation steps:
Affected products:
deepobj
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-46509
https://github.com/ranfdev/deepobj/security/advisories/GHSA-x7q7-fchv-8h2j
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
