CVE-2026-59876

protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 until 8.6.5, the protobufjs Text Format extension parsed string-keyed map entries using ordinary property assignment, allowing a map entry with key __proto__ to change the prototype of the returned map object instead of creating an own map entry in protobufjs/ext/textformat. This issue is fixed in version 8.6.5.
Configurations

Configuration 1 (hide)

cpe:2.3:a:protobufjs_project:protobufjs:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-07-08 16:16

Updated : 2026-07-13 15:02


NVD link : CVE-2026-59876

Mitre link : CVE-2026-59876

CVE.ORG link : CVE-2026-59876


JSON object : View

Products Affected

protobufjs_project

  • protobufjs
CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')