Prototype Pollution Vulnerability in Form-Data-Objectizer by KasperNJ
CVE-2026-46510
8.2HIGH
What is CVE-2026-46510?
The form-data-objectizer library, which transforms FormData into JavaScript objects, contains a vulnerability that allows for prototype pollution. Specifically, prior to version 1.0.1, it incorrectly handles bracket-notation keys, allowing an attacker to exploit names beginning with 'proto'. This flaw can lead to unintended modifications in the Object.prototype, creating potential security risks across the entire Node.js environment. Users are strongly advised to upgrade to version 1.0.1 to mitigate this issue.
Affected Version(s)
form-data-objectizer < 1.0.1
