CVE-2026-46509 – deepobj: Improperly Controlled Modification of Object Prototype Attributes (‘Prototype Pollution’)

​CVE ID :CVE-2026-46509

Published : May 28, 2026, 7:16 p.m. | 31 minutes ago

Description :deepobj provides get, set, delete deep objects in javascript. Prior to 1.0.3, prototype pollution is possible when property paths contain __proto__/constructor/prototype. The property path must not be exposed as user input. This vulnerability is fixed in 1.0.3.

Severity: 8.2 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more… To Read More Visit Read More