CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-54335

lowCVSS 3.7covered by 2 sourcesfirst seen 2026-07-14
Impact The _.merge(target, source) utility exported by @feathersjs/commons recursively merges source into target by iterating Object.keys(source). When source was produced by JSON.parse and contains a proto (or constructor / prototype) key, that key is returned as an own-enumerable property. The recursive merge then resolves target['proto'] to Object.prototype and writes the attacker-supplied properties onto it, polluting the prototype for all plain objects in the process for the lifetime of the Node process. Scope of real-world risk is limited. No first-party Feathers package routes input — trusted or untrusted — through commons._.merge. The @feathersjs/authentication package, which does merge request-influenced data, uses lodash/merge (prototype-pollution-safe since 4.17.12), not this utility. Exploitation therefore requires a downstream plugin or application to pass JSON-parsed, attacker-controlled input directly through the exported _.merge. Patches Fixed in @feathersjs/commons@5.0.45. The fix skips proto, constructor, and prototype keys during iteration — the standard remediation used by lodash and others. Workarounds Avoid passing JSON-parsed untrusted input through commons._.merge. Freezing Object.prototype or validating/sanitizing keys upstream also mitigates. Credit Reported responsibly by Andrew Ridings (@ridingsa).

⚡ Watch CVE-2026-54335

Get an email if CVE-2026-54335 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-54335

CVE.org record

Embed the live status

CVE-2026-54335 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-54335 status](https://www.csirts.com/badge/CVE-2026-54335)](https://www.csirts.com/cve/CVE-2026-54335)