CVE-2026-103036
Received Received - Intake

Prototype Pollution in oRPC JSON Schema Coercion

Vulnerability report for CVE-2026-103036, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: GitHub, Inc.

Description

oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.9, the @orpc/json-schema SmartCoercionPlugin uses JsonSchemaCoercer to collect object properties in a plain object and to resolve schema.properties entries through the prototype chain. A remote client that can reach a procedure with an object input schema can supply __proto__ to replace the prototype of the single coerced request object, or supply Object.prototype member names such as constructor and toString so inherited values are treated as sub-schemas and pass the coercer's satisfaction check. Attacker-controlled inherited properties can consequently affect handler, Object.assign, or configuration lookups, while legitimate __proto__ properties are dropped. The global Object.prototype, unrelated objects, other requests, and other users are not modified, and downstream schema validation still runs. This issue is fixed in version 1.14.9.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-03
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
middleapi orpc 1.14.9
middleapi json-schema to 1.14.9 (exc)
orpc orpc 1.14.9

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-915 The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.
CWE-1321 The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a prototype injection issue in the @orpc/json-schema package affecting versions before 1.14.9. It occurs in the JsonSchemaCoercer component which mishandles object keys that are Object.prototype members during smart coercion. Attackers can manipulate the prototype of the coerced input object by including keys like __proto__ or constructor in their payload. This does not result in global prototype pollution but can cause the coerced object to inherit attacker-controlled properties, potentially leading to unintended behavior in the application.

Detection Guidance

To detect this vulnerability, check if your system uses the @orpc/json-schema package version <= 1.14.8. Run commands like 'npm list @orpc/json-schema' or 'yarn list @orpc/json-schema' to verify the installed version. If the version is vulnerable, update to 1.14.9 or later.

Impact Analysis

An attacker could supply malicious input containing __proto__ or constructor keys to influence the behavior of the coerced object. This might lead to unintended property inheritance, incorrect schema validation, or unexpected application logic. The impact is limited to the single request carrying the payload and does not affect other objects or requests globally.

Compliance Impact

This vulnerability could indirectly impact compliance with standards like GDPR and HIPAA by enabling prototype pollution attacks that manipulate object properties during API request processing. Attackers could inject malicious properties into coerced objects, potentially leading to unauthorized data access or modification if the application relies on the coerced input for security-sensitive operations. However, the issue is scoped to a single request and does not modify global prototypes or other objects, limiting its broader impact.

Mitigation Strategies

Immediately update the @orpc/json-schema package to version 1.14.9 or later. If updating is not possible, reject payloads containing __proto__, constructor, or prototype keys. Alternatively, remove the SmartCoercionPlugin if coercion is unnecessary.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103036. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart