A AegiFlow
HIGHCVSS 7.8EPSS 0.4%

CVE-2026-8657

jsondiffpatch patch APIs are vulnerable to prototype pollution

Published
2026-05-16
Modified
2026-08-31
EPSS percentile
31%
Aliases
GHSA-j4fx-xxwh-2485
Sources
github-advisory

Summary

Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Prototype Pollution via the jsondiffpatch.patch() and jsondiffpatch/formatters/jsonpatch.patch() APIs. An attacker can perform prototype pollution by supplying crafted delta or JSON Patch documents, as attacker-controlled property names and path segments are used to traverse and modify objects without restricting access to special properties like __proto__ or constructor.prototype, allowing modification of Object.prototype.

Affected packages

EcosystemPackageAffected versionsFixed versions
npmjsondiffpatch0.7.6

Remediation: Upgrade to 0.7.6 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.