Remote Procedure Call Plugin Vulnerability in oRPC by MiddleAPI
CVE-2026-103918
6.5MEDIUM
What is CVE-2026-103918?
The oRPC API tool prior to version 1.14.10 contains a vulnerability in the @orpc/zod ZodSmartCoercionPlugin. This issue allows remote clients to manipulate prototype chains by supplying proto within object or record inputs. Consequently, this can lead to unexpected inherited values influencing application logic during lookups, potentially resulting in unhandled TypeErrors during validation. The flaw affects only crafted requests and does not affect global object integrity or state across users. A patch has been implemented in version 1.14.10 to mitigate this risk.
Affected Version(s)
orpc < 1.14.10
