CVE-2026-103918
Received Received - Intake

oRPC ZodSmartCoercionPlugin Prototype Pollution Vulnerability

Vulnerability report for CVE-2026-103918, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: GitHub, Inc.

Description

oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.10, the @orpc/zod ZodSmartCoercionPlugin and experimental_ZodSmartCoercionPlugin collect object and record properties in plain objects and resolve shape keys through the prototype chain. A remote client that can reach a procedure with an object or record input can supply __proto__ to replace the prototype of the returned request object, allowing attacker-controlled inherited values to reach application lookups. For object schemas, keys such as constructor, toString, and __proto__ can instead resolve inherited members as Zod schemas and cause an unhandled TypeError before validation. The global Object.prototype, unrelated objects, other requests, and other users are not modified, and the availability effect is limited to crafted requests rather than persistent process-wide state. This issue is fixed in version 1.14.10.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-03
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
middleapi orpc 1.14.10
orpc zod to 1.14.10 (exc)
zodsmartcoercionplugin orpc to 1.14.10 (exc)
experimental_zodsmartcoercionplugin orpc to 1.14.10 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-915 The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.
CWE-1321 The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a prototype injection flaw in the oRPC library's ZodSmartCoercionPlugin and experimental_ZodSmartCoercionPlugin. It occurs when these plugins process object or record inputs before validation. Attackers can manipulate prototype properties like __proto__, constructor, or toString in their input payloads. This allows them to inject properties into the prototype chain of the coerced input object, potentially influencing how the application processes the input. The issue is fixed in version 1.14.10 by using a null prototype object to prevent prototype manipulation.

The vulnerability does not enable global prototype pollution as no shared or global state is modified. The impact is limited to crafted requests and does not affect other requests or the global Object.prototype.

Detection Guidance

Detecting this vulnerability requires checking if your system uses affected versions of @orpc/zod (prior to 1.14.10). Inspect package.json files for dependencies on @orpc/zod and verify installed versions using commands like npm list @orpc/zod or yarn list @orpc/zod. Additionally, monitor logs for TypeErrors related to prototype chain issues during input validation.

Impact Analysis

An attacker could exploit this to influence how your application processes input data. For example, if your code checks input.isAdmin, an attacker might trick it into reading attacker-controlled data from the prototype chain instead of the actual input. This could lead to unauthorized access or incorrect data processing in the affected request.

The impact is limited to the specific crafted request and does not persist across requests or modify global state. However, it could cause application errors or unexpected behavior during request processing.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing attackers to manipulate input validation through prototype injection. For GDPR, this might affect data integrity and security measures for personal data processing. For HIPAA, it could compromise the integrity of health-related data handling in APIs. The limited scope to crafted requests reduces but does not eliminate compliance risks.

Mitigation Strategies

Upgrade to @orpc/zod version 1.14.10 or later immediately. If upgrading is not possible, remove the ZodSmartCoercionPlugin or experimental_ZodSmartCoercionPlugin from your application. Alternatively, implement input validation to reject payloads containing dangerous keys like __proto__, constructor, or toString.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103918. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart