Remote Procedure Call Plugin Vulnerability in oRPC by MiddleAPI
CVE-2026-103918

6.5MEDIUM

Key Information:

Vendor

Middleapi

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-103918?

The oRPC API tool prior to version 1.14.10 contains a vulnerability in the @orpc/zod ZodSmartCoercionPlugin. This issue allows remote clients to manipulate prototype chains by supplying proto within object or record inputs. Consequently, this can lead to unexpected inherited values influencing application logic during lookups, potentially resulting in unhandled TypeErrors during validation. The flaw affects only crafted requests and does not affect global object integrity or state across users. A patch has been implemented in version 1.14.10 to mitigate this risk.

Affected Version(s)

orpc < 1.14.10

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.