{"id":"GHSA-8hq7-ggx2-cc6m","summary":"msgpack5: Partial options disable prototype protection","details":"### Impact\n\nPassing an empty or partial options object disables the default `protoAction: 'error'` protection. A map containing a `__proto__` key can then replace the prototype of the decoded object, potentially changing inherited properties or causing unexpected behavior in downstream code.\n\nOnly the decoded object's prototype is affected; this does not modify `Object.prototype` globally.\n\n### Patches\n\nOptions are now merged with secure defaults without modifying the caller's object. Unsupported `protoAction` values are rejected.\n\n### Workarounds\n\nExplicitly set `protoAction: 'error'` whenever constructing a msgpack5 instance, and validate decoded values before use.","aliases":["CVE-2026-107301"],"modified":"2026-10-08T18:00:08.899286917Z","published":"2026-10-08T17:39:57Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-1321"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-10-08T17:39:57Z"},"references":[{"type":"WEB","url":"https://github.com/mcollina/msgpack5/security/advisories/GHSA-8hq7-ggx2-cc6m"},{"type":"WEB","url":"https://github.com/mcollina/msgpack5/commit/20e82600ac9462e679c8a45e5723315f21e2c774"},{"type":"PACKAGE","url":"https://github.com/mcollina/msgpack5"},{"type":"WEB","url":"https://github.com/mcollina/msgpack5/releases/tag/v6.1.0"}],"affected":[{"package":{"name":"msgpack5","ecosystem":"npm","purl":"pkg:npm/msgpack5"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"6.1.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-8hq7-ggx2-cc6m/GHSA-8hq7-ggx2-cc6m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L"}]}