← Back to CVE List
CVE-2026-106448NVD
Vulnerability Summary
StableLib is a stable library of useful TypeScript and JavaScript code. Prior to 2.0.4, the @stablelib/cbor CBOR map decoding path creates ordinary JavaScript objects and assigns attacker-controlled keys with bracket assignment. A map key named __proto__ invokes the inherited prototype setter instead of creating an ordinary own property, allowing the decoded object's prototype to contain attacker-controlled authorization or feature-flag values. Downstream code that trusts normal property lookup or merges the decoded object can therefore make security-sensitive decisions using inherited attacker data. This issue is fixed in version 2.0.4.
CVSS v4.0 Base Metrics — Score 8.9 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsPresent
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)High
Availability (Vulnerable System)None
Confidentiality (Subsequent System)None
Integrity (Subsequent System)High
Availability (Subsequent System)None
Affected & Patched Versions
- StableLib stablelib >= < 2.0.4
Not provided by cveorg for this CVE.