🔐 CVE Alert

CVE-2026-106550

UNKNOWN 0.0

CVE-2026-106550

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Mozilla's Node-convict (version 6.2.2 and later) is vulnerable to a Denial of Service vulnerability caused by incomplete prototype‑pollution protections in config.set(). An attacker controlling the configuration key can write arbitrary properties to constructor.<key>, which walk() resolves to the global Object function. This allows overwriting core JavaScript methods such as Object.assign, leading to persistent process-wide failures and requiring a restart. The issue bypasses existing filters that only block constructor.prototype.* and __proto__.*. Exploitation requires an endpoint that forwards attacker-controlled keys into config.set().

Vendor mozilla
Product node-convict
Ecosystems
Industries
Technology
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for mozilla node-convict

Be the first to know when new unknown vulnerabilities affecting mozilla node-convict are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Mozilla / Node-convict
6.2.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/mozilla/node-convict