Description
flat-to-nested converts a hierarchy from a flat representation to a nested representation. Prior to 1.1.2, FlatToNested.prototype.convert in index.js uses attacker-influenced id and parent record fields directly as keys in the plain temp and pendingChildOf objects. When parent or id is __proto__, temp[parent] can resolve to Object.prototype, and initPush() can write attacker-controlled data to the global children prototype property while existing prototype methods remain intact. Any application that passes attacker-influenced flat records to convert() can therefore expose unrelated objects to polluted inherited state, causing application-logic corruption or denial of service and potentially enabling greater impact when a downstream prototype-pollution gadget is present. The constructor and prototype strings are also unsafe inherited-key values in the same lookup design. This issue is fixed in version 1.1.2.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Prototype pollution leading to application logic corruption
Action: Immediate Patch
AI Analysis

Impact

flat-to-nested-js transforms flat hierarchy data into a nested JSON structure. Before version 1.1.2, its convert() function used attacker‑influenced values from the id and parent fields as object keys in temporary structures. If those values were set to "__proto__", the key resolved to Object.prototype, allowing the function to write attacker‑controlled properties onto the global prototype. Applications that pass untrusted flat records to convert() could thus poison the prototype chain, leading to logic corruption or a denial of service. The flaw is a classic prototype‑pollution weakness (CWE‑1321) and also violates safe key handling (CWE‑915).

Affected Systems

Any project that incorporates joaonuno:flat-to-nested-js prior to release v1.1.2 is impacted. The library is typically used to convert flat hier in a variety of JavaScript applications that rely on its public convert() function. Version information is explicitly limited to versions earlier than 1.1.2; all newer releases are considered safe.

Risk and Exploitability

The CVSS score of 7.5 indicates the vulnerability is in the high severity range. The EPSS score of < 1% indicates a very low but non‑zero probability of exploitation. The issue is not listed in CISA’s KEV catalog, suggesting that exploitation may not be widespread yet. Attackers would need to supply crafted flat records to the convert() method, which is typically a public function or one invoked with externally sourced data. If the application does not validate or sanitize these input objects, prototype pollution can be triggered, providing a vector for logic corruption or a chain to more serious consequences if a downstream gadget is deployed. There are no existing public exploits, but the conditions for exploitation are straightforward and could be automated in a typical environment where flatToNested is used.

Generated by OpenCVE AI on September 20, 2026 at 23:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade joaonuno/flat-to-nested-js to version 1.1.2 or later. This replaces the vulnerable convert() implementation that no longer uses __proto__ as a key.
  • If an upgrade is not immediately possible, ensure that all id and parent fields in data passed to convert() are validated and sanitized so they cannot contain "__proto__" or other prototype keys. Reject or strip such values before processing.
  • Implement a runtime layer that detects prototype prototype modifications or logs unexpected changes to Object.prototype to surface potential abuse early.

Generated by OpenCVE AI on September 20, 2026 at 23:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-hp36-v28f-w3r4 flat-to-nested: Prototype pollution in flat-to-nested convert() via __proto__ parent/id key
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Joaonuno
Joaonuno flat-to-nested-js
Vendors & Products Joaonuno
Joaonuno flat-to-nested-js

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description flat-to-nested converts a hierarchy from a flat representation to a nested representation. Prior to 1.1.2, FlatToNested.prototype.convert in index.js uses attacker-influenced id and parent record fields directly as keys in the plain temp and pendingChildOf objects. When parent or id is __proto__, temp[parent] can resolve to Object.prototype, and initPush() can write attacker-controlled data to the global children prototype property while existing prototype methods remain intact. Any application that passes attacker-influenced flat records to convert() can therefore expose unrelated objects to polluted inherited state, causing application-logic corruption or denial of service and potentially enabling greater impact when a downstream prototype-pollution gadget is present. The constructor and prototype strings are also unsafe inherited-key values in the same lookup design. This issue is fixed in version 1.1.2.
Title flat-to-nested: Prototype pollution in flat-to-nested convert() via __proto__ parent/id key
Weaknesses CWE-1321
CWE-915
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Joaonuno Flat-to-nested-js
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T20:05:59.070Z

Reserved: 2026-06-16T14:41:54.578Z

Link: CVE-2026-55091

cve-icon Vulnrichment

Updated: 2026-09-14T19:22:12.825Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:17:54.790

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-55091

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:15:04Z

Weaknesses
  • CWE-1321

    Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

  • CWE-915

    Improperly Controlled Modification of Dynamically-Determined Object Attributes