CVE-2026-107353
Received Received - Intake

Prototype Pollution in traverse npm Package

Vulnerability report for CVE-2026-107353, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: harborist

Description

traverse (npm) versions 0.3.6 through 0.3.9, 0.4.0 through 0.4.6, 0.5.0 through 0.5.2, and 0.6.0 through 0.6.11 allow prototype pollution through set(). When the path passed to set() crosses a primitive value, the next path segment is resolved on that primitive's built-in prototype, so an application that passes an untrusted path to set() lets an attacker add or overwrite properties of String.prototype, Number.prototype, or Boolean.prototype using plain JSON data, for example traverse({ name: 'bob' }).set(['name', '__proto__', 'polluted'], 'yes'). Object.prototype was reachable only with a non-data path segment, such as an object whose toString returns a different value on each call, or through a Proxy that accepts an assignment without storing it. This is fixed in 0.3.10, 0.4.7, 0.5.3, and 0.6.12.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-08
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
ljharb traverse 0.3.6
ljharb traverse 0.4.0
ljharb traverse 0.5.0
ljharb traverse 0.6.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1321 The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a prototype pollution flaw in the npm package traverse versions 0.3.6 through 0.6.11. The set() method allows attackers to modify built-in prototypes like String.prototype or Object.prototype by passing untrusted paths containing __proto__. This happens because the method traverses paths by creating missing objects, and if a path crosses a primitive value, the next segment is resolved on that primitive's prototype.

Detection Guidance

To detect this vulnerability, check if your system uses vulnerable versions of the traverse npm package (0.3.6 to 0.3.9, 0.4.0 to 0.4.6, 0.5.0 to 0.5.2, or 0.6.0 to 0.6.11). Run: npm list traverse. If installed, verify the version matches the vulnerable range.

Impact Analysis

An attacker could exploit this to add or overwrite properties on shared prototypes using plain JSON data. This could affect the entire JavaScript process, leading to unexpected behavior, crashes, or security bypasses in applications using vulnerable versions of traverse.

Mitigation Strategies

Immediately update the traverse package to a patched version (>= 0.3.10, >= 0.4.7, >= 0.5.3, or >= 0.6.12). Run: npm update traverse. If updating is not possible, avoid passing untrusted paths to the set() method or validate all path segments.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107353. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart