Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104183— stream-json: Prototype pollution: Assembler writes this.current[this.key] on plain objects

Quick assessment

Affected
uhop stream-json
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

stream-json 是一个用于处理 JSON 和 JSONC 的流组件微型库,具有极小的内存占用。在 3.6.0 版本之前,Assembler(组装器)通过普通赋值来实例化对象属性。因此,当输入中包含名为 的键时,会触发继承的 setter(设置器),导致解析后的对象原型被替换,而不是创建一个自身的数据属性。 如果应用程序基于继承的值进行授权或功能决策,就可能消费到由攻击者控制的属性;此外,空原型(null prototype)可能会干扰那些期望使用 方法的代码。 研究人员认为,解析不可信的 JSON 属于该项

CVSS 5.1 · Medium EPSS 0.19% · P8

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
uhop stream-json < 3.6.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104183

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
stream-json: Prototype pollution: Assembler writes this.current[this.key] on plain objects
Source: CVE Program / CVE List V5
Vulnerability Description
stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, Assembler materializes object properties with plain assignment, so an input key named __proto__ invokes the inherited setter and causes parsed object prototype replacement instead of creating an own data property. Applications that make authorization or feature decisions from inherited values can therefore consume attacker-controlled properties, and a null prototype can disrupt code that expects Object.prototype methods. The researcher treats parsing untrusted JSON as part of the project contract, while the maintainer states that documented inputs are locally owned dumps, exports, or logs and characterizes the attack vector as local. The global Object.prototype is not polluted. This issue is fixed in version 3.6.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1321
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
uhop stream-json < 3.6.0 -

II. Public POCs for CVE-2026-104183

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104183

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-104183 (1)

Vendor Advisories for CVE-2026-104183 (1)

Vendor Pages for CVE-2026-104183 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-104183

No comments yet


Leave a comment