{"id":"CVE-2026-46681","summary":"@nevware21/ts-utils: Prototype Pollution in objDeepCopy/objCopyProps via for...in without hasOwnProperty","details":"@nevware21/ts-utils is a comprehensive TypeScript/JavaScript utility library. Prior to version 0.14.0, the _copyProps function in lib/src/object/copy.ts uses for...in to iterate over source object properties without an Object.hasOwnProperty check, and does not filter dangerous keys (__proto__, constructor, prototype). This allows an attacker to pollute the prototype chain of all objects in the application. Version 0.14.0 patches the issue.","aliases":["GHSA-x7j8-49r8-mr43"],"modified":"2026-07-23T04:03:00.243385099Z","published":"2026-07-21T14:02:03.732Z","database_specific":{"cwe_ids":["CWE-1321"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46681.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46681.json"},{"type":"ADVISORY","url":"https://github.com/nevware21/ts-utils/security/advisories/GHSA-x7j8-49r8-mr43"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46681"},{"type":"FIX","url":"https://github.com/nevware21/ts-utils/commit/5e887f4e2fbee7160c8f501634c45e6a229e83bb"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nevware21/ts-utils","events":[{"introduced":"0"},{"fixed":"5e887f4e2fbee7160c8f501634c45e6a229e83bb"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"0.14.0"}]}}],"versions":["0.13.0","0.12.6","0.12.5","0.12.4","0.12.3","0.12.2","0.12.1","0.12.0","0.11.8","0.11.7","0.11.6","0.11.5","0.11.4","0.11.3","0.11.2","0.11.1","0.11.0","0.10.5","0.10.4","0.10.3","0.10.2","0.10.1","0.10.0","0.9.8","0.9.7","0.9.6","0.9.5","0.9.4","0.9.3","0.9.2","0.9.1","0.9.0","0.8.1","0.3.4","0.8.0","0.7.3","0.7.2","0.7.1","0.7.0","0.6.0","0.5.0","0.4.6","0.4.5","0.4.4","0.4.3","0.4.2","0.4.1","0.4.0","0.3.3","0.3.2","0.3.1","0.3.0","0.2.0","0.1.1","0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-46681.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U"}]}