Prototype Manipulation Vulnerability in stream-json by Uhop
CVE-2026-104183
5.1MEDIUM
What is CVE-2026-104183?
The stream-json library, designed for processing JSON and JSONC with a low memory footprint, has a vulnerability prior to version 3.6.0. Due to how object properties are materialized, a key named proto can trigger inherited setters, leading to unintended prototype replacement. This can expose applications to attacker-controlled properties, particularly in contexts where authorization relies on inherited values. Such manipulation could compromise application integrity, especially if a null prototype is introduced, undermining the expected behavior of Object.prototype methods. This issue has been addressed and resolved in version 3.6.0.
Affected Version(s)
stream-json < 3.6.0
