Description
traverse (npm) versions 0.3.6 through 0.3.9, 0.4.0 through 0.4.6, 0.5.0 through 0.5.2, and 0.6.0 through 0.6.11 allow prototype pollution through set(). When the path passed to set() crosses a primitive value, the next path segment is resolved on that primitive's built-in prototype, so an application that passes an untrusted path to set() lets an attacker add or overwrite properties of String.prototype, Number.prototype, or Boolean.prototype using plain JSON data, for example traverse({ name: 'bob' }).set(['name', '__proto__', 'polluted'], 'yes'). Object.prototype was reachable only with a non-data path segment, such as an object whose toString returns a different value on each call, or through a Proxy that accepts an assignment without storing it. This is fixed in 0.3.10, 0.4.7, 0.5.3, and 0.6.12.
Published: 2026-10-07
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Prototype Pollution with Potential Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from the set() function in the traverse package, which allows an attacker controlling an untrusted path argument to write properties onto built‑in JavaScript prototypes such as String.prototype, Number.prototype, or Boolean.prototype. This prototype pollution (CWE‑1321) means that the application may unintentionally alter the behavior of every object that relies on those prototypes, potentially enabling arbitrary code execution, tampering of application logic, or denial of service.

Affected Systems

The affected product is the npm package "traverse", authored by ljharb (GitHub repository js‑traverse). All releases from 0.3.6 through 0.3.9, 0.4.0 through 0.4.6, 0.5.0 through 0.5.2, and 0.6.0 through 0.6.11 are vulnerable. The latest patched releases are 0.3.10, 0.4.7, 0.5.3, and 0.6.12 or newer.

Risk and Exploitability

The CVSS score of 6.9 indicates a high severity impact that can be achieved when the set() call receives untrusted input. EPSS is not available, so the exploitation probability cannot be quantified, and the vulnerability is not currently listed in the CISA KEV catalogue. Based on the description, the attack vector is likely remote or network‑based if an attacker can supply input that reaches the set() function, for example through a REST endpoint or a plugin that forwards user data to traverse. A successful exploit would enable the attacker to inject properties into prototypes, which may subsequently lead to arbitrary code execution or data tampering.

Generated by OpenCVE AI on October 7, 2026 at 20:21 UTC.

Remediation

Vendor Solution

Upgrade to traverse 0.6.12 or later, or, on older release lines, to 0.5.3, 0.4.7, or 0.3.10.


Vendor Workaround

Do not pass untrusted paths to set(). If that is not possible, require every path segment to be a string other than __proto__, constructor, or prototype, and confirm that each intermediate value along the path is an object before calling set().


OpenCVE Recommended Actions

  • Upgrade the traverse package to a fixed release (0.6.12 or newer, or to 0.5.3, 0.4.7, or 0.3.10).
  • If updating is not feasible, avoid passing any untrusted paths to set().
  • If untrusted paths must be used, filter the path array to block segments named __proto__, constructor, or prototype, and verify that each segment is a valid string and that each intermediate value is an object before calling set().

Generated by OpenCVE AI on October 7, 2026 at 20:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description traverse (npm) versions 0.3.6 through 0.3.9, 0.4.0 through 0.4.6, 0.5.0 through 0.5.2, and 0.6.0 through 0.6.11 allow prototype pollution through set(). When the path passed to set() crosses a primitive value, the next path segment is resolved on that primitive's built-in prototype, so an application that passes an untrusted path to set() lets an attacker add or overwrite properties of String.prototype, Number.prototype, or Boolean.prototype using plain JSON data, for example traverse({ name: 'bob' }).set(['name', '__proto__', 'polluted'], 'yes'). Object.prototype was reachable only with a non-data path segment, such as an object whose toString returns a different value on each call, or through a Proxy that accepts an assignment without storing it. This is fixed in 0.3.10, 0.4.7, 0.5.3, and 0.6.12.
Title traverse: set() can write to built-in prototypes via an untrusted path
Weaknesses CWE-1321
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: harborist

Published:

Updated: 2026-10-07T20:37:09.233Z

Reserved: 2026-10-07T19:20:21.848Z

Link: CVE-2026-107353

cve-icon Vulnrichment

Updated: 2026-10-07T20:37:04.058Z

cve-icon NVD

Status : Received

Published: 2026-10-07T20:17:11.860

Modified: 2026-10-07T21:17:15.537

Link: CVE-2026-107353

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T20:30:13Z

Weaknesses
  • CWE-1321

    Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')