Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.8 Node.js & npm GHSA-325j-mg25-8q58 CVE-2026-61534

Prototype Pollution in Yayson JSON:API Library (CVE-2026-61534)

Yayson versions up to and including 4.2.0 contain a critical prototype pollution vulnerability in their Store and LegacyStore deserialization logic, allowing attacker-controlled JSON:API documents to pollute Object.prototype. Version 4.3.0 fixes the issue.

Synthesized by AI from 2 sources · updated 1 hour ago

AI summary

A critical vulnerability has been disclosed in Yayson, a JavaScript library used to serialize and read JSON:API data. The flaw, tracked as CVE-2026-61534 (GHSA-325j-mg25-8q58), allows attacker-controlled JSON:API documents to pollute JavaScript's Object.prototype, with consequences ranging from denial of service to application logic corruption. The issue affects all versions up to and including 4.2.0 and is fixed in 4.3.0.

What Happened

A prototype pollution vulnerability was identified in Yayson's Store and LegacyStore deserialization code (src/yayson/store.ts and src/yayson/legacy-store.ts). These components use attacker-controlled values from JSON:API documents — specifically the 'type', 'id', and relationship names — as keys in plain JavaScript object lookup tables without sanitization. A document that sets its type to '__proto__' causes the model cache to write directly into Object.prototype, with the attacker controlling the property name via the document's 'id' field and the value via its 'attributes'.

Technical Cause

The root cause is CWE-1321 (Improperly Controlled Modification of Object Prototype Attributes). Because Store and LegacyStore use unsanitized JSON:API 'type', 'id', and relationship identifiers as object keys, special property names such as '__proto__', 'constructor', and 'prototype' are not filtered out. This allows a maliciously crafted document — including one supplied via an 'included' resource — to reach and modify Object.prototype. LegacyStore is also reachable when an application's configured types mapping resolves to '__proto__', providing an additional attack path.

Why It Matters

Prototype pollution affects all objects in a JavaScript process, since Object.prototype is shared globally. This can cause denial of service by corrupting shared object behavior, and can corrupt application logic in unpredictable ways. The advisory notes that further impact — such as authorization bypass or remote code execution — depends on whether the consuming application contains 'gadgets' (code paths that can be exploited once prototype properties are polluted). No such gadgets are confirmed in this advisory; the baseline impact described is denial of service and logic corruption.

Who Is Affected

Any application using the yayson npm package to deserialize JSON:API data from untrusted or external sources is potentially affected, since the vulnerability is triggered by processing attacker-supplied documents through Store or LegacyStore.

Affected Versions

All yayson versions from 0 up to and including 4.2.0 are affected.

Fixes and Mitigation

The vulnerability is fixed in yayson version 4.3.0. Organizations using yayson should upgrade to 4.3.0 or later.

Recommended Action

Update yayson to version 4.3.0 as soon as possible, particularly for applications that process JSON:API data originating from external or untrusted sources. After upgrading, review application logs for anomalous behavior that might indicate prior exploitation attempts, and audit any custom gadget code paths that could be affected by prototype pollution.

PatchBriefing score

5.8 / 10 · Medium

Official CVSS: 9.1

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Why this score

This vulnerability carries a CVSS base score of 9.1 (Critical), reflecting that it is exploitable over the network (AV:N) with low attack complexity (AC:L), requires no privileges (PR:N) and no user interaction (UI:N), and can cause high integrity and availability impact (I:H, A:H) with no confidentiality impact (C:N). PatchBriefing's computed score of 5.8 factors in the high CVSS base score along with the facts that the vulnerability is remotely exploitable without authentication and requires no user interaction. The score does not include boosts for known exploitation in the wild, public exploit code, or elevated EPSS likelihood, none of which apply here, and reflects a fix already being available.

Affected versions

yayson <= 4.2.0
vulnerable
≥ 4.3.0
patched

Reported fixes

The vulnerability is fixed in yayson version 4.3.0. Organizations using yayson should upgrade to 4.3.0 or later.

How this was built

2 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • NVD (NIST) database
Unified report
Prototype Pollution in Yayson JSON:API Library (CVE-2026-61534)
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email