๐Ÿ” CVE Alert

CVE-2026-106448

UNKNOWN 0.0

StableLib: Prototype poisoning via `__proto__` map keys in CBOR decoding

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

StableLib is a stable library of useful TypeScript and JavaScript code. Prior to 2.0.4, the @stablelib/cbor CBOR map decoding path creates ordinary JavaScript objects and assigns attacker-controlled keys with bracket assignment. A map key named __proto__ invokes the inherited prototype setter instead of creating an ordinary own property, allowing the decoded object's prototype to contain attacker-controlled authorization or feature-flag values. Downstream code that trusts normal property lookup or merges the decoded object can therefore make security-sensitive decisions using inherited attacker data. This issue is fixed in version 2.0.4.

CWE CWE-1321
Vendor stablelib
Product stablelib
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for stablelib stablelib

Be the first to know when new unknown vulnerabilities affecting stablelib stablelib are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

StableLib / stablelib
< 2.0.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/StableLib/stablelib/security/advisories/GHSA-w48f-fwg7-ww6p github.com: https://github.com/StableLib/stablelib/commit/0f153a63b7552a0e8721f640984113e419015026 github.com: https://github.com/StableLib/stablelib/releases/tag/@stablelib/[email protected]