{"id":"GHSA-hf2r-9gf9-rwch","summary":"Convict has prototype pollution via load(), loadFile(), and schema initialization","details":"### Impact\nTwo unguarded prototype pollution paths exist, not covered by previous fixes:\n\n1. `config.load()` / `config.loadFile()` — `overlay()` recursively merges config data without checking for forbidden keys. Input containing` __proto__` or `constructor.prototype` (e.g. from a JSON file) causes the recursion to reach `Object.prototype` and write attacker-controlled values onto it.\n2. Schema initialization — passing a schema with `constructor.prototype.*` keys to `convict({...})` causes default-value propagation to write directly to `Object.prototype` at startup.\n\nDepending on how polluted properties are consumed, impact ranges from unexpected behavior to authentication bypass or RCE.\n\n### Workarounds\nDo not pass untrusted data to load(), loadFile(), or convict().\n\n### Resources\nPrior advisory: [GHSA-44fc-8fm5-q62h](https://github.com/mozilla/node-convict/security/advisories/GHSA-44fc-8fm5-q62h)\nRelated issue: [https://github.com/mozilla/node-convict/issues/423](https://github.com/mozilla/node-convict/issues/423)","aliases":["CVE-2026-33863"],"modified":"2026-03-26T19:11:25.577317Z","published":"2026-03-26T18:50:33Z","database_specific":{"github_reviewed_at":"2026-03-26T18:50:33Z","nvd_published_at":null,"cwe_ids":["CWE-1321"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/mozilla/node-convict/security/advisories/GHSA-44fc-8fm5-q62h"},{"type":"WEB","url":"https://github.com/mozilla/node-convict/security/advisories/GHSA-hf2r-9gf9-rwch"},{"type":"WEB","url":"https://github.com/mozilla/node-convict/issues/423"},{"type":"PACKAGE","url":"https://github.com/mozilla/node-convict"}],"affected":[{"package":{"name":"convict","ecosystem":"npm","purl":"pkg:npm/convict"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"6.2.5"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 6.2.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-hf2r-9gf9-rwch/GHSA-hf2r-9gf9-rwch.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}]}