Prototype Manipulation Vulnerability in stream-json by Uhop
CVE-2026-104183

5.1MEDIUM

Key Information:

Vendor

Uhop

Vendor
CVE Published:
1 October 2026

What is CVE-2026-104183?

The stream-json library, designed for processing JSON and JSONC with a low memory footprint, has a vulnerability prior to version 3.6.0. Due to how object properties are materialized, a key named proto can trigger inherited setters, leading to unintended prototype replacement. This can expose applications to attacker-controlled properties, particularly in contexts where authorization relies on inherited values. Such manipulation could compromise application integrity, especially if a null prototype is introduced, undermining the expected behavior of Object.prototype methods. This issue has been addressed and resolved in version 3.6.0.

Affected Version(s)

stream-json < 3.6.0

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.