Prototype Pollution in Vaadin Charts and Component Base
CVE-2026-91860

6.3MEDIUM

Key Information:

Vendor

Vaadin

Vendor
CVE Published:
30 September 2026

What is CVE-2026-91860?

A prototype pollution vulnerability has been identified in the deep merge helpers of Vaadin Charts and Vaadin Component Base. This flaw allows untrusted objects to be merged into the chart configuration or the components' internationalization properties, thereby modifying the Object.prototype. As a consequence, any properties injected via this method can potentially be accessed by all objects in the running application. To mitigate this vulnerability, users should update to specified fixed versions. Versions 10-13 and 15-22 of Vaadin are no longer supported.

Affected Version(s)

@vaadin/charts 23.0.0 < 23.6.5

@vaadin/charts 24.0.0 < 24.9.18

@vaadin/charts 24.10.0 < 24.10.5

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ridwan Arefin Islam, Madiba Security Lab, Concordia University
.