GHSA-j4fx-xxwh-2485
HIGHCVE-2026-8657Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Prototype Pollution via the jsondiffpatch.patch() and jsondiffpatch/formatters/jsonpatch.patch() APIs. An attacker can perform prototype pollution by supplying crafted delta or JSON Patch documents, as attacker-controlled property names and path segments are used to traverse and modify objects without restricting access to specia
- Affected
- < 0.7.6
- Fixed in
- 0.7.6
- Weakness
- CWE-1321
- Published
- 2026-05-16
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereference