Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107301— msgpack5: Partial options disable prototype protection

Quick assessment

Affected
mcollina msgpack5
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

msgpack5 是一个适用于 Node.js 和浏览器的 MessagePack v5 实现。在版本 6.1.0 之前,如果使用空或部分初始化的 options 对象构造 msgpack5 实例,将禁用默认的 protoAction: 'error' 保护机制。此时,若解码得到的消息包中包含一个 __proto__ 键,该键可能导致解码对象的 prototype 被替换,从而可能改变其继承的属性或影响下游行为(尽管不会全局修改 Object.prototype)。该问题已在版本 6.1.0 中得到修复。

CVSS 6.5 · Medium

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
mcollina msgpack5 < 6.1.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107301

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
msgpack5: Partial options disable prototype protection
Source: CVE Program / CVE List V5
Vulnerability Description
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, constructing msgpack5 with an empty or partial options object disables the default protoAction: 'error' protection. A decoded map containing a __proto__ key can then replace the decoded object's prototype, potentially changing inherited properties or downstream behavior, although Object.prototype is not modified globally. This issue is fixed in version 6.1.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1321
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
mcollina msgpack5 < 6.1.0 -

II. Public POCs for CVE-2026-107301

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107301

请登录查看更多情报信息。

Other References for CVE-2026-107301 (3)

Same Patch Batch · mcollina · 2026-10-08 · 7 CVEs total

CVE-2026-107300 7.5 HIGH msgpack5: Many buffered values can exhaust the streaming decoder stack
CVE-2026-107302 7.5 HIGH msgpack5: Truncated map32 headers throw an unexpected error
CVE-2026-107297 5.9 MEDIUM msgpack5: Quadratic parsing in the streaming decoder
CVE-2026-107299 5.9 MEDIUM msgpack5: Reserved byte can cause unbounded stream buffering
CVE-2026-107298 5.3 MEDIUM msgpack5: Deeply nested input can exhaust the decoder stack
CVE-2026-107296 3.7 LOW msgpack5: Decoding negative int64 values mutates the input buffer

IV. Related Vulnerabilities

V. Comments for CVE-2026-107301

No comments yet


Leave a comment