Prototype Pollution Issue in Software Mansion React Native Worklets
CVE-2026-97724
5.3MEDIUM
What is CVE-2026-97724?
A prototype pollution vulnerability exists in Software Mansion's React Native Worklets versions before 0.12.2. This vulnerability allows an attacker to pass an object with a proto property that can alter the prototype of objects during serialization in the clonePlainJSObject function. As a result, if these malformed serialized objects are processed, it can lead to application crashes and potentially cause denial of service in React Native applications. If the attacker-controlled data is stored, the disruption could persist even after application restarts, making it a significant concern for developers and users managing applications with sensitive or dynamic unvalidated data.
Affected Version(s)
React Native Reanimated Android worklets-0.5.0
