Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-106448— StableLib: Prototype poisoning via `__proto__` map keys in CBOR decoding

Quick assessment

Affected
StableLib stablelib
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

StableLib 是一个包含有用 TypeScript 和 JavaScript 代码的稳定库。在版本 2.0.4 之前,@stablelib/cbor 组件中的 CBOR 映射解码路径会创建普通的 JavaScript 对象,并使用方括号赋值方式将攻击者控制的键分配给该对象。当映射键名为 时,系统会调用继承的 prototype setter,而不是创建普通的自有属性,从而导致解码后的对象的 prototype 可能包含攻击者控制的授权或功能标志(feature-flag)值。下游代码若信任正常的属性查找或合并

CVSS 8.9 · High

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
StableLib stablelib < 2.0.4 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-106448

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
StableLib: Prototype poisoning via `__proto__` map keys in CBOR decoding
Source: CVE Program / CVE List V5
Vulnerability Description
StableLib is a stable library of useful TypeScript and JavaScript code. Prior to 2.0.4, the @stablelib/cbor CBOR map decoding path creates ordinary JavaScript objects and assigns attacker-controlled keys with bracket assignment. A map key named __proto__ invokes the inherited prototype setter instead of creating an ordinary own property, allowing the decoded object's prototype to contain attacker-controlled authorization or feature-flag values. Downstream code that trusts normal property lookup or merges the decoded object can therefore make security-sensitive decisions using inherited attacker data. This issue is fixed in version 2.0.4.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1321
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
StableLib stablelib < 2.0.4 -

II. Public POCs for CVE-2026-106448

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-106448

请登录查看更多情报信息。

Other References for CVE-2026-106448 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-106448

No comments yet


Leave a comment