๐Ÿ” CVE Alert

CVE-2026-107353

MEDIUM 6.5

traverse: set() can write to built-in prototypes via an untrusted path

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

traverse (npm) versions 0.3.6 through 0.3.9, 0.4.0 through 0.4.6, 0.5.0 through 0.5.2, and 0.6.0 through 0.6.11 allow prototype pollution through set(). When the path passed to set() crosses a primitive value, the next path segment is resolved on that primitive's built-in prototype, so an application that passes an untrusted path to set() lets an attacker add or overwrite properties of String.prototype, Number.prototype, or Boolean.prototype using plain JSON data, for example traverse({ name: 'bob' }).set(['name', '__proto__', 'polluted'], 'yes'). Object.prototype was reachable only with a non-data path segment, such as an object whose toString returns a different value on each call, or through a Proxy that accepts an assignment without storing it. This is fixed in 0.3.10, 0.4.7, 0.5.3, and 0.6.12.

CWE CWE-1321
Vendor ljharb
Product traverse
Published Oct 7, 2026
Last Updated Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for ljharb traverse

Be the first to know when new medium vulnerabilities affecting ljharb traverse are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low

Affected Versions

ljharb / traverse
0.3.6 < 0.3.10 0.4.0 < 0.4.7 0.5.0 < 0.5.3 0.6.0 < 0.6.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/ljharb/js-traverse/security/advisories/GHSA-rj28-8w7x-jmqc github.com: https://github.com/ljharb/js-traverse/commit/81ccab43e379cf42eb2a5f689630f7f79b3d71b8 github.com: https://github.com/ljharb/js-traverse/commit/37a9ebd103d2a259c824c29cdcc3f0dfe1acffce