Vulnerability DatabaseCVE-2026-106448

CVE-2026-106448: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-106448 is a prototype pollution vulnerability in the @stablelib/cbor CBOR decoding library, classified as "Prototype Poisoning via __proto__ map keys in CBOR decoding." The flaw affects all versions of @stablelib/cbor prior to 2.0.4 and was disclosed on October 6, 2026, with the fix released on April 2, 2026 (tagged @stablelib/cbor@2.0.4). It carries a CVSS v4.0 base score of 8.9 (High) (GitHub Advisory, Feedly).

Technical details

The root cause is CWE-1321 (Improperly Controlled Modification of Object Prototype Attributes — Prototype Pollution). The @stablelib/cbor decoder builds map results using a plain {} object and assigns attacker-controlled keys via bracket notation (e.g., result[key] = value). In JavaScript, assigning to obj["__proto__"] does not create an own property — it invokes the built-in __proto__ setter, replacing the object's prototype with the attacker-supplied value. A crafted CBOR payload containing a map entry with key __proto__ and value { isAdmin: true } will therefore cause the decoded object's prototype to carry attacker-controlled properties, which are then visible through normal property lookup on any object in the prototype chain. The fix (commit 0f153a6) adds an explicit blocklist check that throws a "cbor: forbidden map key" error for keys __proto__, constructor, and prototype in both definite and indefinite map decoding paths (GitHub Advisory, Fix Commit).

Impact

Successful exploitation allows an unauthenticated remote attacker to inject arbitrary properties into the JavaScript object prototype chain of any object decoded from untrusted CBOR input. This can corrupt authorization checks (e.g., causing obj.isAdmin to return true for all objects), manipulate feature flags, and alter application logic that relies on normal property lookup rather than strict own-property checks. If the decoded object is subsequently merged into other objects (e.g., via Object.assign or spread operators), the pollution can propagate further across the application, amplifying the integrity impact to downstream systems (GitHub Advisory, Feedly).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been observed as of the disclosure date. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the attacker to be able to supply a malicious CBOR-encoded message to an application that decodes it using @stablelib/cbor, which is a realistic precondition for any network-facing service accepting CBOR input (Feedly, GitHub Advisory).

Exploitation steps

  1. Identify target: Locate a network-accessible application that accepts CBOR-encoded input and uses @stablelib/cbor versions prior to 2.0.4 for decoding (e.g., via npm package inspection or API endpoint analysis).
  2. Craft malicious CBOR payload: Construct a CBOR map containing a __proto__ key whose value is a map with the desired injected property, such as { isAdmin: true }. The raw bytes for this payload are: 0xa1 0x69 0x5f 0x5f 0x70 0x72 0x6f 0x74 0x6f 0x5f 0x5f 0xa1 0x67 0x69 0x73 0x41 0x64 0x6d 0x69 0x6e 0xf5.
  3. Submit payload: Send the crafted CBOR payload to the target application endpoint that processes CBOR input (e.g., via HTTP POST with Content-Type: application/cbor).
  4. Trigger prototype pollution: The decoder assigns the __proto__ key via bracket notation, replacing the decoded object's prototype with the attacker-controlled map { isAdmin: true }.
  5. Exploit downstream logic: Any subsequent code that reads obj.isAdmin (or other injected properties) via normal property lookup will receive the attacker-supplied value true, potentially bypassing authorization checks or enabling privilege escalation within the application (GitHub Advisory, Fix Commit).

Indicators of compromise

  • Network: Unexpected or malformed CBOR-encoded HTTP requests (Content-Type: application/cbor) containing byte sequences corresponding to __proto__, constructor, or prototype keys (e.g., hex 695f5f70726f746f5f5f for __proto__).
  • Logs: Application error logs showing cbor: forbidden map key errors (in patched versions) or unexpected authorization grants in access logs that do not correspond to legitimate user credentials.
  • Application Behavior: Unexpected privilege escalation events, feature flags being enabled for users who should not have access, or authorization checks returning true for unauthenticated or low-privilege users.
  • File System: Evidence of @stablelib/cbor versions prior to 2.0.4 in node_modules/@stablelib/cbor/package.json ("version": "2.0.1" or earlier) (GitHub Advisory).

Mitigation and workarounds

The primary remediation is to upgrade @stablelib/cbor to version 2.0.4 or later, which blocks decoding of CBOR maps containing the keys __proto__, constructor, or prototype by throwing an error (GitHub Release, Fix Commit). As a defense-in-depth measure, applications should use Object.hasOwn() or Object.prototype.hasOwnProperty.call() instead of direct property lookups for all security-sensitive decisions such as authorization and feature-flag checks. Additionally, input validation at the API boundary to reject CBOR payloads containing suspicious keys (__proto__, constructor, prototype) can reduce exposure prior to patching (Feedly).

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-106448HIGH8.9
  • JavaScript logoJavaScript
  • @stablelib/cbor
NoYesOct 06, 2026
CVE-2026-106447HIGH8.7
  • JavaScript logoJavaScript
  • @stablelib/cbor
NoYesOct 06, 2026
CVE-2026-105854HIGH8.7
  • JavaScript logoJavaScript
  • payload
NoYesOct 06, 2026
CVE-2026-105855HIGH7.6
  • JavaScript logoJavaScript
  • payload
NoYesOct 06, 2026
CVE-2026-105853HIGH7.1
  • JavaScript logoJavaScript
  • payload
NoYesOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management