Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.4 Node.js & npm GHSA-8hq7-ggx2-cc6m CVE-2026-107301

CVE-2026-107301: msgpack5 prototype protection bypass when constructed with empty or partial options

msgpack5 prior to 6.1.0 can have its default prototype-protection disabled when constructed with an empty or partial options object, allowing a decoded map containing a __proto__ key to replace the decoded object's prototype. Fixed in 6.1.0. [source: 4128, 31829]

Synthesized by AI from 2 sources · updated 1 hour ago

AI summary

A prototype-protection bypass was reported in msgpack5, a MessagePack implementation for Node.js and browsers. The issue can occur when msgpack5 is constructed with an empty or partial options object, which can disable the default protoAction: 'error' setting and allow a decoded map containing a __proto__ key to replace an object's prototype. A fix is available. [4128, 31829]

What happened

Constructing msgpack5 with an empty or partial options object disables the package's default protoAction: 'error' protection. When that protection is disabled, a decoded MessagePack map that contains a __proto__ key can replace the prototype of the decoded object, potentially changing inherited properties or downstream behavior. The issue does not modify Object.prototype globally. [4128, 31829]

Technical cause

The default protoAction setting (protoAction: 'error') is not enforced if msgpack5 is constructed with an empty or partial options object. That configuration gap permits a decoded map with a __proto__ key to be applied as the decoded object's prototype. The advisory describes this behavior and the resulting prototype replacement. [4128, 31829]

Why it matters

Replacing a decoded object's prototype can change inherited properties or affect downstream code that relies on those properties, which may alter application behavior or logic after decoding untrusted input. The advisory indicates the potential for changed inherited properties or downstream behavior; it also notes Object.prototype is not modified globally. [4128, 31829]

Who is affected

Users of the msgpack5 library (Node.js and browser environments) who construct msgpack5 with an empty or partial options object are affected. Decoding untrusted MessagePack data under those construction conditions is where the described behavior can occur. [4128, 31829]

Discovery and timeline

The advisory entries for this issue were published on 2026-10-08. The OSV.dev entry and NVD record are the public sources referenced for this advisory. The package advisory metadata lists publication and modification timestamps. [4128, 31829]

Affected versions

The advisory claims msgpack5 is affected from version 0 up to (but not including) 6.1.0. [4128]

Fixes and mitigation

A fix is available: the advisory states the issue is fixed in 6.1.0. The advisory does not provide other mitigation steps. [4128, 31829]

Recommended action

Upgrade msgpack5 to 6.1.0. If you cannot upgrade immediately, avoid constructing msgpack5 with an empty or partial options object where feasible and treat MessagePack inputs from untrusted sources as untrusted until the environment is updated. The advisory identifies the construction-with-empty-or-partial-options condition as the trigger for disabled protection. [4128, 31829]

PatchBriefing score

4.4 / 10 · Medium

Official CVSS: 6.5

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L

Why this score

CVSS base score is 6.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L) as reported in the advisory. PatchWire score for this advisory is 4.4; contributing factors listed in the advisory include an unauthenticated remote vector (contribution +0.6) and no required user interaction (contribution +0.2), alongside the CVSS base contribution. The advisory also indicates no known public exploit and no known active exploitation. [4128, 31829]

Affected versions

msgpack5 ≥ 0 < 6.1.0
vulnerable
≥ 6.1.0
patched

Reported fixes

A fix is available: the advisory states the issue is fixed in 6.1.0. The advisory does not provide other mitigation steps. [4128, 31829]

How this was built

2 source records were collected, matched and used to prepare the report above.

  • OSV.dev database
  • NVD (NIST) database
Unified report
CVE-2026-107301: msgpack5 prototype protection bypass when constructed with empty or partial options
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email