Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-97724

Quick assessment

Affected
swmansion React Native Reanimated
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Software Mansion React Native Worklets 在 0.12.2 版本之前存在原型链污染漏洞。攻击者可通过构造包含 属性的恶意对象,修改在 文件中 函数序列化过程中创建的对象的原型链。 当受污染的数据随后被 React Native Worklets 处理时,这种格式错误的序列化对象会导致 React Native 应用程序崩溃。在那些将攻击者可控数据通过受影响序列化路径传递的应用程序中,这可能引发远程触发的拒绝服务(DoS)攻击。对于持久化存储攻击者可控数据的应用程序,拒绝服务现象可

CVSS 4.3 · Medium EPSS 0.25% · P15

Affected Version Matrix 1

VendorProduct Version RangeStatus
swmansion React Native Reanimated worklets-0.5.0< worklets-0.12.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-97724

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
A prototype pollution vulnerability in Software Mansion React Native Worklets before 0.12.2 allows an attacker-controlled object containing a __proto__ property to modify the prototype of an object created during serialization in clonePlainJSObject in packages/react-native-worklets/src/memory/serializable.native.ts. When affected data is subsequently processed by React Native Worklets, the malformed serialized object can cause the React Native application to crash. This can result in a remotely triggered denial of service in applications that pass attacker-controlled data through the affected serialization path. In applications where the attacker-controlled data is persisted, the denial of service may persist across application restarts or repeated attempts to access the affected content.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1321
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
swmansion React Native Reanimated worklets-0.5.0 ~ worklets-0.12.2 -

II. Public POCs for CVE-2026-97724

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-97724

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-97724 (2)

News Coverage for CVE-2026-97724 (1)

Vendor Pages for CVE-2026-97724 (1)

Other References for CVE-2026-97724 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-97724

No comments yet


Leave a comment