Prototype Pollution Vulnerability in StableLib by StableLib
CVE-2026-106448

8.9HIGH

Key Information:

Vendor

Stablelib

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106448?

A vulnerability exists in the handling of CBOR map decoding in StableLib prior to version 2.0.4, where arbitrary JavaScript objects can be created. Attackers may exploit this flaw by injecting malicious keys, such as 'proto', which can overwrite the prototype of the decoded object. This could lead to unauthorized access or modifications, as downstream code that relies on standard property lookup may inadvertently trust or execute with attacker-controlled data, potentially compromising security sensitive operations.

Affected Version(s)

stablelib < 2.0.4

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.