Security Flaw in oRPC API Tool by MiddleAPI
CVE-2026-103036
6.5MEDIUM
What is CVE-2026-103036?
Prior to version 1.14.9, oRPC's @orpc/json-schema SmartCoercionPlugin could be exploited through object input schemas. Attackers were able to supply the proto property or Object.prototype member names, allowing them to manipulate inherited properties of the coerced request object. This could lead to unintended effects on other operations like handler evaluations or configuration lookups while bypassing certain security validations. The flaw has been addressed in version 1.14.9, which eliminates the potential for such prototype pollution attacks.
Affected Version(s)
orpc < 1.14.9
