Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9,
Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An atta
Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method inj
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated
A weakness has been identified in jsonata-js jsonata up to 2.2.0. The affected element is the function createFrame of th
A security vulnerability has been detected in RubyLouvre avalon up to 2.2.10. The impacted element is an unknown functio
Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a prototype pollution vulnerabilit
A weakness has been identified in carboneio carbone up to fbcd349077ad0e8748be73eab2a82ea92b6f8a7e. This impacts an unkn
A vulnerability was identified in higuma web-audio-recorder-js 0.1/0.1.1. Impacted is the function extend in the library
CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.2.0, the Series Chart opera
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, an authenticated user with org-leve
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulne
Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-sid
protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 until 8.6.5, the protobufjs Text For
Hono before 4.12.7 allows __proto__ key in parseBody with dot option enabled, permitting specially crafted form field na
Hey API is an ecosystem for turning API specifications into production-ready code. Prior to 0.97.3, dist/clients/core/pa
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolve
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A Prototype Pollution condition in th
OpenClaw versions prior to 2026.2.21 accept prototype-reserved keys in runtime /debug set override object values, allowi
Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering she
A security flaw has been discovered in enquirer up to 2.4.1. Affected is the function Enquirer.set of the component Publ
A vulnerability was detected in tanstack db up to 0.6.8. Affected by this vulnerability is the function select of the fi
SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fi
Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in
Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created b
Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In 5.0.44 and
A vulnerability was found in Lagom WHMCS Template up to 2.3.7. Impacted is an unknown function of the component Datatabl
In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities. In versions prior
Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities. Versions prior to
@nevware21/ts-utils is a comprehensive TypeScript/JavaScript utility library. Prior to version 0.14.0, the _copyProps fu
Pivotick used plain JavaScript objects as lookup tables indexed by caller-controlled graph node identifiers in its tree-
axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/a
axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype h
axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the Edit Fields (Set) node. The
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engine. An aut
ApostropheCMS is an open-source Node.js content management system. In 4.32.0 and earlier, PATCH /api/v1/article/:id acce
Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter proces
n8n is a workflow automation platform. In versions prior to 1.123.69, 2.33.4, and 2.34.1, the JavaScript Code node's VM
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (becau
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates
Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked
An issue was discovered in CMS Made Simple 2.2.8. In the module ModuleManager (in the file action.installmodule.php), it
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Import module by a Regular user.
assign-deep is vulnerable to Prototype Pollution in versions before 0.4.8 and version 1.0.0. The function assign-deep co
In RPyC 4.1.x through 4.1.1, a remote attacker can dynamically modify object attributes to construct a remote procedure
In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototy
Frequently Asked Questions
What is CWE-1321?
CWE-1321 (CWE-1321) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-1321?
There are 162 CVE records associated with CWE-1321 in our database. Of these, 27 are critical severity, 62 are high severity, and 52 are medium severity.
How can I protect against CWE-1321 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-1321 using AI-powered security agents.
Detect CWE-1321 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-1321 vulnerabilities across your infrastructure.
Get Started