Impact
The node‑opcua library contains a flaw in the fieldsToJson function used in the client_alarm module. Unsanitized field names are assigned directly, allowing a __proto__ path to reach Object.prototype and overwrite properties on all objects. If an attacker can supply event field names, the prototype may be polluted, leading to denial of service or corrupted application logic. The weakness is classified as Prototype Pollution (CWE‑1321).
Affected Systems
Node‑opcua:node‑opcua is affected. Versions prior to node‑opcua-client 2.145.0 contain the vulnerability. The issue applies only to the client package and its related alarm modules.
Risk and Exploitability
The CVSS base score of 3.7 indicates low severity. The EPSS score below 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA KEV. Exploitation requires the application to forward attacker‑controlled event fields to fieldsToJson, which is typically a remote or untrusted input scenario. If achieved, prototype pollution can break object prototypes, potentially causing denial of service or affecting application logic.
OpenCVE Enrichment