Impact
Yayson, a JSON‑API deserialization library, treated the document's type, id, and relationship names as keys in plain‑object maps. When the type value is "__proto__", the library writes into Object.prototype, enabling an attacker to pollute prototype properties with values derived from the document's id and attributes. An included resource can also supply the malicious type, and unsafe relationship names such as "__proto__", "constructor", and "prototype" provide additional paths for pollution. The resulting process‑wide prototype pollution can corrupt inheritance chains, cause denial of service or logic corruption, and, in applications containing exploitable gadget chains, lead to authorization bypass or code execution. The issue is addressed in Yayson 4.3.0.
Affected Systems
The vulnerable library is Confetti Yayson. Any installation using Yayson versions prior to 4.3.0 that performs deserialization of JSON‑API data is susceptible. Applications that depend on Yayson 4.2.x or earlier and consume untrusted JSON‑API payloads are at risk.
Risk and Exploitability
The CVSS score of 9.1 signifies a high risk. The EPSS score indicates a very low exploitation probability (<1%), so the exact likelihood vulnerability is not listed in the CISA KEV catalog. The attack requires an attacker to provide crafted JSON‑API input that is processed by Yayson, making the likely vector remote data ingestion. If the consuming application contains gadget chains, exploitation can lead to code execution; otherwise the impact is limited to denial of service or logic corruption.
OpenCVE Enrichment
Github GHSA