Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107353— traverse: set() can write to built-in prototypes via an untrusted path

Quick assessment

Affected
ljharb traverse
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

npm 包 traverse 在版本 0.3.6 至 0.3.9、0.4.0 至 0.4.6、0.5.0 至 0.5.2 以及 0.6.0 至 0.6.11 中存在原型污染漏洞,该漏洞通过 set() 方法触发。当传递给 set() 的路径跨越一个原始值(primitive value)时,路径的下一段将在该原始值内建原型(built-in prototype)上进行解析。因此,如果应用程序将不受信任的路径传递给 set(),攻击者即可利用纯 JSON 数据对 String.prototype、Number.pro

CVSS 6.5 · Medium

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 4

VendorProduct Version RangeStatus
ljharb traverse 0.3.6< 0.3.10 affected
0.4.0< 0.4.7 affected
0.5.0< 0.5.3 affected
0.6.0< 0.6.12 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107353

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
traverse: set() can write to built-in prototypes via an untrusted path
Source: CVE Program / CVE List V5
Vulnerability Description
traverse (npm) versions 0.3.6 through 0.3.9, 0.4.0 through 0.4.6, 0.5.0 through 0.5.2, and 0.6.0 through 0.6.11 allow prototype pollution through set(). When the path passed to set() crosses a primitive value, the next path segment is resolved on that primitive's built-in prototype, so an application that passes an untrusted path to set() lets an attacker add or overwrite properties of String.prototype, Number.prototype, or Boolean.prototype using plain JSON data, for example traverse({ name: 'bob' }).set(['name', '__proto__', 'polluted'], 'yes'). Object.prototype was reachable only with a non-data path segment, such as an object whose toString returns a different value on each call, or through a Proxy that accepts an assignment without storing it. This is fixed in 0.3.10, 0.4.7, 0.5.3, and 0.6.12.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1321
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ljharb traverse 0.3.6 ~ 0.3.10 -

II. Public POCs for CVE-2026-107353

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107353

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-107353 (2)

Vendor Advisories for CVE-2026-107353 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-107353

No comments yet


Leave a comment