Impact
The Assembler component of stream-json constructs parsed JSON objects by direct property assignment. When a key named "__proto__" is encountered, the assignment invokes the inherited setter and replaces the object's prototype rather than creating an own data property. This prototype manipulation can cause applications that perform authorization or feature decisions based on inherited values to use attacker‑controlled properties, and a null prototype can break code that expects Object.prototype methods. The flaw is a prototype‑pollution weakness (CWE‑1321) that enables altered object behavior, potentially leading to privilege escalation or denial of service within the application.
Affected Systems
Vendor uhop provides the stream‑json library. The vulnerability exists in all published releases prior to version 3.6.0. No specific operating systems or platforms are listed; the library is JavaScript‑based and can be used in any Node.js or browser environment that incorporates the vulnerable package. Users who rely on uhop:stream‑json as a dependency should verify whether their installed version is below 3.6.0.
Risk and Exploitability
The CVSS base score of 5.1 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in KEV. The documented attack vector is local, meaning an attacker must be able to supply malicious JSON to the application that uses stream‑json. If the code processes untrusted data, an attacker could exploit the prototype‑pollution flaw to alter application logic or break functionality. While exploitation does not automatically provide remote code execution, the impact on authorization controls and application stability makes timely mitigation advisable.
OpenCVE Enrichment