CVE-2026-107301
Received Received - Intake

Prototype Pollution in msgpack5 Library

Vulnerability report for CVE-2026-107301, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, constructing msgpack5 with an empty or partial options object disables the default protoAction: 'error' protection. A decoded map containing a __proto__ key can then replace the decoded object's prototype, potentially changing inherited properties or downstream behavior, although Object.prototype is not modified globally. This issue is fixed in version 6.1.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mcollina msgpack5 < 6.1.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1321 The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

msgpack5 is a MessagePack v5 implementation for Node.js and browsers. Prior to version 6.1.0, passing an empty or partial options object to msgpack5 disables the default protoAction: 'error' protection. This allows a decoded map containing a __proto__ key to alter the object's prototype, potentially changing inherited properties or downstream behavior without modifying Object.prototype globally.

Detection Guidance

To detect this vulnerability, check the version of msgpack5 in your project using npm list msgpack5 or npm ls msgpack5. If the version is below 6.1.0, the system is vulnerable. Additionally, review code that uses msgpack5 to ensure protoAction is explicitly set to 'error' in options.

Impact Analysis

An attacker could exploit this to manipulate object prototypes during deserialization, leading to unexpected behavior in applications using msgpack5 versions before 6.1.0. This might cause crashes, incorrect data handling, or unintended property inheritance in affected systems.

Compliance Impact

This vulnerability could lead to data integrity issues or unauthorized access if exploited, potentially violating GDPR (data protection) or HIPAA (health data security) requirements. Organizations must ensure patched versions are used to maintain compliance.

Mitigation Strategies

Update msgpack5 to version 6.1.0 or later to restore the default protoAction: 'error' protection and prevent prototype pollution via __proto__ keys.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107301. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart