CVE-2026-33228

flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the internal input buffer is a JavaScript Array, accessing it with the key "__proto__" returns Array.prototype via the inherited getter. This object is then treated as a legitimate parsed value and assigned as a property of the output object, effectively leaking a live reference to Array.prototype to the consumer. Any code that subsequently writes to that property will pollute the global prototype. This issue has been patched in version 3.4.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:webreflection:flatted:*:*:*:*:*:node.js:*:*

History

02 Jul 2026, 12:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:34342 -

27 Jun 2026, 05:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:13826 -
  • () https://access.redhat.com/errata/RHSA-2026:9742 -
  • () https://access.redhat.com/security/cve/CVE-2026-33228 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2449872 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33228.json -
CWE CWE-915

17 Jun 2026, 10:37

Type Values Removed Values Added
Summary
  • (es) flatted es un analizador de JSON circular. Antes de la versión 3.4.2, la función parse() en flatted puede usar valores de cadena controlados por el atacante del JSON analizado como claves de índice de array directas, sin validar que sean numéricos. Dado que el búfer de entrada interno es un Array de JavaScript, acceder a él con la clave '__proto__' devuelve Array.prototype a través del getter heredado. Este objeto es entonces tratado como un valor analizado legítimo y asignado como una propiedad del objeto de salida, filtrando efectivamente una referencia en vivo a Array.prototype al consumidor. Cualquier código que posteriormente escriba en esa propiedad contaminará el prototipo global. Este problema ha sido parcheado en la versión 3.4.2.

23 Mar 2026, 19:14

Type Values Removed Values Added
CPE cpe:2.3:a:webreflection:flatted:*:*:*:*:*:node.js:*:*
First Time Webreflection
Webreflection flatted
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://github.com/WebReflection/flatted/commit/885ddcc33cf9657caf38c57c7be45ae1c5272802 - () https://github.com/WebReflection/flatted/commit/885ddcc33cf9657caf38c57c7be45ae1c5272802 - Patch
References () https://github.com/WebReflection/flatted/releases/tag/v3.4.2 - () https://github.com/WebReflection/flatted/releases/tag/v3.4.2 - Product
References () https://github.com/WebReflection/flatted/security/advisories/GHSA-rf6f-7fwh-wjgh - () https://github.com/WebReflection/flatted/security/advisories/GHSA-rf6f-7fwh-wjgh - Exploit, Vendor Advisory

20 Mar 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-20 23:16

Updated : 2026-07-15 02:20


NVD link : CVE-2026-33228

Mitre link : CVE-2026-33228

CVE.ORG link : CVE-2026-33228


JSON object : View

Products Affected

webreflection

  • flatted
CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

CWE-915

Improperly Controlled Modification of Dynamically-Determined Object Attributes