Description
stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, Assembler materializes object properties with plain assignment, so an input key named __proto__ invokes the inherited setter and causes parsed object prototype replacement instead of creating an own data property. Applications that make authorization or feature decisions from inherited values can therefore consume attacker-controlled properties, and a null prototype can disrupt code that expects Object.prototype methods. The researcher treats parsing untrusted JSON as part of the project contract, while the maintainer states that documented inputs are locally owned dumps, exports, or logs and characterizes the attack vector as local. The global Object.prototype is not polluted. This issue is fixed in version 3.6.0.
Published: 2026-10-01
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Prototype pollution enabling altered object behavior
Action: Update Library
AI Analysis

Impact

The Assembler component of stream-json constructs parsed JSON objects by direct property assignment. When a key named "__proto__" is encountered, the assignment invokes the inherited setter and replaces the object's prototype rather than creating an own data property. This prototype manipulation can cause applications that perform authorization or feature decisions based on inherited values to use attacker‑controlled properties, and a null prototype can break code that expects Object.prototype methods. The flaw is a prototype‑pollution weakness (CWE‑1321) that enables altered object behavior, potentially leading to privilege escalation or denial of service within the application.

Affected Systems

Vendor uhop provides the stream‑json library. The vulnerability exists in all published releases prior to version 3.6.0. No specific operating systems or platforms are listed; the library is JavaScript‑based and can be used in any Node.js or browser environment that incorporates the vulnerable package. Users who rely on uhop:stream‑json as a dependency should verify whether their installed version is below 3.6.0.

Risk and Exploitability

The CVSS base score of 5.1 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in KEV. The documented attack vector is local, meaning an attacker must be able to supply malicious JSON to the application that uses stream‑json. If the code processes untrusted data, an attacker could exploit the prototype‑pollution flaw to alter application logic or break functionality. While exploitation does not automatically provide remote code execution, the impact on authorization controls and application stability makes timely mitigation advisable.

Generated by OpenCVE AI on October 1, 2026 at 21:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install stream‑json version 3.6.0 or later to eliminate the prototype‑pollution issue.
  • Audit any code paths that feed user‑supplied JSON into stream‑json and ensure that the data is trusted or sanitized before parsing.
  • Implement input validation to reject or encode keys containing "__proto__" or other prototype‑related names if upgrading is not immediately possible.

Generated by OpenCVE AI on October 1, 2026 at 21:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Uhop
Uhop stream-json
Vendors & Products Uhop
Uhop stream-json

Thu, 01 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Description stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, Assembler materializes object properties with plain assignment, so an input key named __proto__ invokes the inherited setter and causes parsed object prototype replacement instead of creating an own data property. Applications that make authorization or feature decisions from inherited values can therefore consume attacker-controlled properties, and a null prototype can disrupt code that expects Object.prototype methods. The researcher treats parsing untrusted JSON as part of the project contract, while the maintainer states that documented inputs are locally owned dumps, exports, or logs and characterizes the attack vector as local. The global Object.prototype is not polluted. This issue is fixed in version 3.6.0.
Title stream-json: Prototype pollution: Assembler writes this.current[this.key] on plain objects
Weaknesses CWE-1321
References
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Uhop Stream-json
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-01T20:30:54.674Z

Reserved: 2026-10-01T18:54:15.118Z

Link: CVE-2026-104183

cve-icon Vulnrichment

Updated: 2026-10-01T20:29:44.271Z

cve-icon NVD

Status : Received

Published: 2026-10-01T21:17:19.197

Modified: 2026-10-01T21:17:19.197

Link: CVE-2026-104183

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T22:00:17Z

Weaknesses
  • CWE-1321

    Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')