CVE-2026-104183
Received Received - Intake

Prototype Pollution in stream-json via __proto__ Key

Vulnerability report for CVE-2026-104183, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: GitHub, Inc.

Description

stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, Assembler materializes object properties with plain assignment, so an input key named __proto__ invokes the inherited setter and causes parsed object prototype replacement instead of creating an own data property. Applications that make authorization or feature decisions from inherited values can therefore consume attacker-controlled properties, and a null prototype can disrupt code that expects Object.prototype methods. The researcher treats parsing untrusted JSON as part of the project contract, while the maintainer states that documented inputs are locally owned dumps, exports, or logs and characterizes the attack vector as local. The global Object.prototype is not polluted. This issue is fixed in version 3.6.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1321 The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in stream-json before version 3.6.0 allows an attacker to manipulate object prototypes by using a key named __proto__ in JSON input. This causes the parser to replace inherited properties instead of creating new ones, potentially altering application behavior.

Detection Guidance

This vulnerability can be detected by checking the version of stream-json in use. If your application uses stream-json and the version is below 3.6.0, it is vulnerable. Run commands like 'npm list stream-json' or 'npm list stream-json@<version>' to check the installed version.

Impact Analysis

This could allow attackers to inject malicious properties into objects, bypass authorization checks, or disrupt application logic that relies on standard Object.prototype methods. The impact includes potential privilege escalation or denial of service.

Mitigation Strategies

Immediately update stream-json to version 3.6.0 or later. If updating is not possible, consider removing or replacing the library with a secure alternative. Review code that parses untrusted JSON to ensure it does not rely on inherited properties or prototype behavior.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104183. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart