CVE-2026-107353
Publication date 8 October 2026
Last updated 8 October 2026
Ubuntu priority
Cvss 3 Severity Score
Description
traverse (npm) versions 0.3.6 through 0.3.9, 0.4.0 through 0.4.6, 0.5.0 through 0.5.2, and 0.6.0 through 0.6.11 allow prototype pollution through set(). When the path passed to set() crosses a primitive value, the next path segment is resolved on that primitive's built-in prototype, so an application that passes an untrusted path to set() lets an attacker add or overwrite properties of String.prototype, Number.prototype, or Boolean.prototype using plain JSON data, for example traverse({ name: 'bob' }).set(['name', '__proto__', 'polluted'], 'yes'). Object.prototype was reachable only with a non-data path segment, such as an object whose toString returns a different value on each call, or through a Proxy that accepts an assignment without storing it. This is fixed in 0.3.10, 0.4.7, 0.5.3, and 0.6.12.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| node-traverse | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
Severity score breakdown
CVSS version:
Base score
6.9 · Medium
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Base score
6.5 · Medium
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
References
Other references
- https://www.cve.org/CVERecord?id=CVE-2026-107353
- https://github.com/ljharb/js-traverse/security/advisories/GHSA-rj28-8w7x-jmqc
- https://github.com/ljharb/js-traverse/commit/81ccab43e379cf42eb2a5f689630f7f79b3d71b8 (v0.6.12)
- https://github.com/ljharb/js-traverse/commit/37a9ebd103d2a259c824c29cdcc3f0dfe1acffce (v0.6.12)
- https://github.com/ljharb/js-traverse/commit/37a9ebd103d2a259c824c29cdcc3f0dfe1acffce
- https://github.com/ljharb/js-traverse/commit/81ccab43e379cf42eb2a5f689630f7f79b3d71b8