CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-33228

Critical · CVSS 9.8

flatted — Prototype Pollution via unsanitized array index key in JSON parser

CVSS
9.8
nvd
EPSS
0.81%
53th pct
KEV
No
Class
oss containerizable
CWE-1321, CWE-915

Description

flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the internal input buffer is a JavaScript Array, accessing it with the key "__proto__" returns Array.prototype via the inherited getter. This object is then treated as a legitimate parsed value and assigned as a property of the output object, effectively leaking a live reference to Array.prototype to the consumer. Any code that subsequently writes to that property will pollute the global prototype. This issue has been patched in version 3.4.2.

Search profile — drives PoC discovery

Symbols parse()__proto__Array.prototypeinput bufferarray index keyscircular JSON parserGHSA-rf6f-7fwh-wjgh
Keywords CVE-2026-33228flatted prototype pollutionflatted parse __proto__flatted circular JSON prototype pollutionnpm flatted CWE-1321flatted 3.4.2 patchWebReflection flatted GHSA-rf6f-7fwh-wjghflatted array index pollution PoC
Versions: <3.4.2

Affected packages

npm flatted 0 → 3.4.2

References

Status: enriched · ingested 2026-06-27T06:00:38.000Z · profiled 2026-07-01T06:30:14.000Z