AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-33228.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 8.9CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 05, 2026

Disclosure summary

--- **Summary** The parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the internal input buffer is a JavaScript Array, accessing it with the key "\_\_proto\_\_" returns Array.prototype via the inherited getter. This object is then treated as a legitimate parsed value and assigned as a property of the output object, effectively leaking a live reference to Array.prototype to the consumer. Any code that subsequently writes to that property will pollute the global prototype. --- **Root Cause** File: esm/index.js:29 (identical in cjs/index.js) ``` const resolver = (input, lazy, parsed, $) => output => { for (let ke = keys(output), {length} = ke, y = 0; y < length; y++) { const k = ke[y]; const value = output[k]; if (value instanceof Primitive) { const tmp = input[value]; // Bug is here ``` No validation that value is a safe numeric index input is built as a plain Array. JavaScript's property lookup on arrays traverses the prototype chain for non-numeric keys. The key "\_\_proto\_\_" resolves to Array.prototype, which: - has type "object" → passes the typeof tmp === object

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

Splunk Security Advisories · SPLUNK-SVD-2026-0805

Open original source · Updated Oct 06, 2026

Third-Party Package Updates in Splunk SOAR - August 2026

Vendor advisory association; do not assume every product in a grouped advisory is affected by each CVE.

GitHub Reviewed Security Advisories · GHSA-rf6f-7fwh-wjgh

Open original source · Updated Oct 05, 2026

Prototype Pollution via parse() in NodeJS flatted

Source severity: HIGH / 8.9

EcosystemPackageAffected rangeFirst patched
npmflatted3.4.2

Original records & references

PUBLISHED 2026-03-19T13:43:54-04:00
MODIFIED 2026-10-05T11:48:47-04:00
INGESTED 2026-10-06T11:45:17-04:00