Disclosure summary
--- **Summary** The parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the internal input buffer is a JavaScript Array, accessing it with the key "\_\_proto\_\_" returns Array.prototype via the inherited getter. This object is then treated as a legitimate parsed value and assigned as a property of the output object, effectively leaking a live reference to Array.prototype to the consumer. Any code that subsequently writes to that property will pollute the global prototype. --- **Root Cause** File: esm/index.js:29 (identical in cjs/index.js) ``` const resolver = (input, lazy, parsed, $) => output => { for (let ke = keys(output), {length} = ke, y = 0; y < length; y++) { const k = ke[y]; const value = output[k]; if (value instanceof Primitive) { const tmp = input[value]; // Bug is here ``` No validation that value is a safe numeric index input is built as a plain Array. JavaScript's property lookup on arrays traverses the prototype chain for non-numeric keys. The key "\_\_proto\_\_" resolves to Array.prototype, which: - has type "object" → passes the typeof tmp === object
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
Splunk Security Advisories · SPLUNK-SVD-2026-0805
Open original source · Updated Oct 06, 2026
Third-Party Package Updates in Splunk SOAR - August 2026
Vendor advisory association; do not assume every product in a grouped advisory is affected by each CVE.
GitHub Reviewed Security Advisories · GHSA-rf6f-7fwh-wjgh
Open original source · Updated Oct 05, 2026
Prototype Pollution via parse() in NodeJS flatted
Source severity: HIGH / 8.9
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | flatted | 3.4.2 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-03-19T13:43:54-04:00
MODIFIED 2026-10-05T11:48:47-04:00
INGESTED 2026-10-06T11:45:17-04:00