{"id":"CVE-2026-107353","summary":"traverse: set() can write to built-in prototypes via an untrusted path","details":"traverse (npm) versions 0.3.6 through 0.3.9, 0.4.0 through 0.4.6, 0.5.0 through 0.5.2, and 0.6.0 through 0.6.11 allow prototype pollution through set(). When the path passed to set() crosses a primitive value, the next path segment is resolved on that primitive's built-in prototype, so an application that passes an untrusted path to set() lets an attacker add or overwrite properties of String.prototype, Number.prototype, or Boolean.prototype using plain JSON data, for example traverse({ name: 'bob' }).set(['name', '__proto__', 'polluted'], 'yes'). Object.prototype was reachable only with a non-data path segment, such as an object whose toString returns a different value on each call, or through a Proxy that accepts an assignment without storing it. This is fixed in 0.3.10, 0.4.7, 0.5.3, and 0.6.12.","aliases":["GHSA-rj28-8w7x-jmqc"],"modified":"2026-10-09T02:49:21.483312315Z","published":"2026-10-07T19:35:15.351Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107353.json","cna_assigner":"harborist","cwe_ids":["CWE-1321"]},"references":[{"type":"WEB","url":"https://www.npmjs.com"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107353.json"},{"type":"ADVISORY","url":"https://github.com/ljharb/js-traverse/security/advisories/GHSA-rj28-8w7x-jmqc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107353"},{"type":"FIX","url":"https://github.com/ljharb/js-traverse/commit/37a9ebd103d2a259c824c29cdcc3f0dfe1acffce"},{"type":"FIX","url":"https://github.com/ljharb/js-traverse/commit/81ccab43e379cf42eb2a5f689630f7f79b3d71b8"},{"type":"PACKAGE","url":"https://github.com/ljharb/js-traverse"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ljharb/js-traverse","events":[{"introduced":"5eab662f486e423e8d1d4bde65c47f99243aa1fe"},{"fixed":"4ba48a1091e18c270faa53587d0fa8366167c554"},{"introduced":"44e731b972b864b1de1ef315bf1ce4dbba3a7d67"},{"fixed":"6a7a19ef57847b98b4ad3ab4195dd35321c39d8f"},{"introduced":"96d9e2564fc0f1413a7a1371cfd9cc5600896771"},{"fixed":"e8017b7d7b88e737b143d6c74a0509fbf7728982"},{"introduced":"aeebf1466c2b7b5660545cc4365b0a66bc54a765"},{"fixed":"2f22287016dabb8e9fd6b84db9834a80cdfb9cdd"}],"database_specific":{"extracted_events":[{"introduced":"0.3.6"},{"fixed":"0.3.10"},{"introduced":"0.4.0"},{"fixed":"0.4.7"},{"introduced":"0.5.0"},{"fixed":"0.5.3"},{"introduced":"0.6.0"},{"fixed":"0.6.12"}],"source":"AFFECTED_FIELD"}}],"versions":["v0.6.11","v0.6.10","v0.6.9","v0.6.8","v0.6.7","v0.6.6","v0.6.5","v0.6.4","v0.6.3","v0.6.2","v0.6.1","v0.6.0","v0.5.2","v0.5.1","v0.5.0","v0.4.6","v0.4.5","v0.4.4","v0.4.3","v0.3.9","v0.3.8","v0.4.2","v0.4.1","v0.4.0","v0.3.7","v0.3.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107353.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"}]}