Description
Yayson is a library for serializing and reading JSON API data in JavaScript. Prior to 4.3.0, Store and LegacyStore use attacker-controlled JSON:API type, id, and relationship names as keys in plain-object lookup tables in src/yayson/store.ts and src/yayson/legacy-store.ts. A document whose type is __proto__ causes model-cache writes to modify Object.prototype, with the attacker controlling the polluted property name through id and its value through attributes. The malicious type can also be supplied by an included resource, and LegacyStore is reachable when a configured types mapping resolves to __proto__. Unsafe relationship names including __proto__, constructor, and prototype provide additional document-derived member paths. The resulting process-wide prototype pollution can cause denial of service and logic corruption; authorization bypass or code execution depends on suitable gadgets in the consuming application. This issue is fixed in version 4.3.0.
Published: 2026-09-14
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Prototype pollution leading to potential denial of service and code execution
Action: Immediate Patch
AI Analysis

Impact

Yayson, a JSON‑API deserialization library, treated the document's type, id, and relationship names as keys in plain‑object maps. When the type value is "__proto__", the library writes into Object.prototype, enabling an attacker to pollute prototype properties with values derived from the document's id and attributes. An included resource can also supply the malicious type, and unsafe relationship names such as "__proto__", "constructor", and "prototype" provide additional paths for pollution. The resulting process‑wide prototype pollution can corrupt inheritance chains, cause denial of service or logic corruption, and, in applications containing exploitable gadget chains, lead to authorization bypass or code execution. The issue is addressed in Yayson 4.3.0.

Affected Systems

The vulnerable library is Confetti Yayson. Any installation using Yayson versions prior to 4.3.0 that performs deserialization of JSON‑API data is susceptible. Applications that depend on Yayson 4.2.x or earlier and consume untrusted JSON‑API payloads are at risk.

Risk and Exploitability

The CVSS score of 9.1 signifies a high risk. The EPSS score indicates a very low exploitation probability (<1%), so the exact likelihood vulnerability is not listed in the CISA KEV catalog. The attack requires an attacker to provide crafted JSON‑API input that is processed by Yayson, making the likely vector remote data ingestion. If the consuming application contains gadget chains, exploitation can lead to code execution; otherwise the impact is limited to denial of service or logic corruption.

Generated by OpenCVE AI on September 20, 2026 at 23:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Yayson to version 4.3.0 or later; this patch removes the prototype pollution vulnerability.
  • If an upgrade is not immediately feasible, sanitize all deserialized JSON‑API data by rejecting or encoding any "type" value of "__proto__" and by filtering out relationship names that match "prototype" before passing them to Yayson.
  • Reconfigure LegacyStore type mappings so that they never resolve to the magic value "__proto__" and disable legacy deserialization paths if they are not required by the application.

Generated by OpenCVE AI on September 20, 2026 at 23:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-325j-mg25-8q58 yayson: Prototype pollution in Store/LegacyStore deserialization
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Confetti
Confetti yayson
Vendors & Products Confetti
Confetti yayson

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Yayson is a library for serializing and reading JSON API data in JavaScript. Prior to 4.3.0, Store and LegacyStore use attacker-controlled JSON:API type, id, and relationship names as keys in plain-object lookup tables in src/yayson/store.ts and src/yayson/legacy-store.ts. A document whose type is __proto__ causes model-cache writes to modify Object.prototype, with the attacker controlling the polluted property name through id and its value through attributes. The malicious type can also be supplied by an included resource, and LegacyStore is reachable when a configured types mapping resolves to __proto__. Unsafe relationship names including __proto__, constructor, and prototype provide additional document-derived member paths. The resulting process-wide prototype pollution can cause denial of service and logic corruption; authorization bypass or code execution depends on suitable gadgets in the consuming application. This issue is fixed in version 4.3.0.
Title Yayson: Prototype pollution in the Store/LegacyStore deserialization
Weaknesses CWE-1321
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T19:19:45.499Z

Reserved: 2026-07-10T16:27:03.093Z

Link: CVE-2026-61534

cve-icon Vulnrichment

Updated: 2026-09-14T19:19:10.572Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T16:17:16.847

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-61534

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:00:08Z

Weaknesses
  • CWE-1321

    Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')