Prototype Pollution Vulnerability in StableLib by StableLib
CVE-2026-106448
8.9HIGH
What is CVE-2026-106448?
A vulnerability exists in the handling of CBOR map decoding in StableLib prior to version 2.0.4, where arbitrary JavaScript objects can be created. Attackers may exploit this flaw by injecting malicious keys, such as 'proto', which can overwrite the prototype of the decoded object. This could lead to unauthorized access or modifications, as downstream code that relies on standard property lookup may inadvertently trust or execute with attacker-controlled data, potentially compromising security sensitive operations.
Affected Version(s)
stablelib < 2.0.4
