Prototype Pollution Issue in Software Mansion React Native Worklets
CVE-2026-97724

5.3MEDIUM

Key Information:

Vendor

Swmansion

Vendor
CVE Published:
25 September 2026

What is CVE-2026-97724?

A prototype pollution vulnerability exists in Software Mansion's React Native Worklets versions before 0.12.2. This vulnerability allows an attacker to pass an object with a proto property that can alter the prototype of objects during serialization in the clonePlainJSObject function. As a result, if these malformed serialized objects are processed, it can lead to application crashes and potentially cause denial of service in React Native applications. If the attacker-controlled data is stored, the disruption could persist even after application restarts, making it a significant concern for developers and users managing applications with sensitive or dynamic unvalidated data.

Affected Version(s)

React Native Reanimated Android worklets-0.5.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.