Prototype Pollution in Vaadin Charts and Component Base
CVE-2026-91860
6.3MEDIUM
What is CVE-2026-91860?
A prototype pollution vulnerability has been identified in the deep merge helpers of Vaadin Charts and Vaadin Component Base. This flaw allows untrusted objects to be merged into the chart configuration or the components' internationalization properties, thereby modifying the Object.prototype. As a consequence, any properties injected via this method can potentially be accessed by all objects in the running application. To mitigate this vulnerability, users should update to specified fixed versions. Versions 10-13 and 15-22 of Vaadin are no longer supported.
Affected Version(s)
@vaadin/charts 23.0.0 < 23.6.5
@vaadin/charts 24.0.0 < 24.9.18
@vaadin/charts 24.10.0 < 24.10.5
References
CVSS V4
Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ridwan Arefin Islam, Madiba Security Lab, Concordia University
