Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to traverse 0.6.12 or later, or, on older release lines, to 0.5.3, 0.4.7, or 0.3.10.
Vendor Workaround
Do not pass untrusted paths to set(). If that is not possible, require every path segment to be a string other than __proto__, constructor, or prototype, and confirm that each intermediate value along the path is an object before calling set().
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | traverse (npm) versions 0.3.6 through 0.3.9, 0.4.0 through 0.4.6, 0.5.0 through 0.5.2, and 0.6.0 through 0.6.11 allow prototype pollution through set(). When the path passed to set() crosses a primitive value, the next path segment is resolved on that primitive's built-in prototype, so an application that passes an untrusted path to set() lets an attacker add or overwrite properties of String.prototype, Number.prototype, or Boolean.prototype using plain JSON data, for example traverse({ name: 'bob' }).set(['name', '__proto__', 'polluted'], 'yes'). Object.prototype was reachable only with a non-data path segment, such as an object whose toString returns a different value on each call, or through a Proxy that accepts an assignment without storing it. This is fixed in 0.3.10, 0.4.7, 0.5.3, and 0.6.12. | |
| Title | traverse: set() can write to built-in prototypes via an untrusted path | |
| Weaknesses | CWE-1321 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: harborist
Published:
Updated: 2026-10-07T20:37:09.233Z
Reserved: 2026-10-07T19:20:21.848Z
Link: CVE-2026-107353
No data.
Status : Received
Published: 2026-10-07T20:17:11.860
Modified: 2026-10-07T20:17:11.860
Link: CVE-2026-107353
No data.
OpenCVE Enrichment
Updated: 2026-10-07T20:30:13Z