Sceawere

Vulnerability Detail

CVE-2026-104183UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

stream-json Prototype Pollution Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.1
Creation Date
1d ago
Vendor
uhop
Product
stream-json
Attack Type
CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, Assembler materializes object properties with plain assignment, so an input key named __proto__ invokes the inherited setter and causes parsed object prototype replacement instead of creating an own data property. Applications that make authorization or feature decisions from inherited values can therefore consume attacker-controlled properties, and a null prototype can disrupt code that expects Object.prototype methods. The researcher treats parsing untrusted JSON as part of the project contract, while the maintainer states that documented inputs are locally owned dumps, exports, or logs and characterizes the attack vector as local. The global Object.prototype is not polluted. This issue is fixed in version 3.6.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.1",
  "pubDate": "2026-10-01T21:17:19.197Z",
  "pubdate": "2026-10-01T21:17:19.197Z",
  "executiveSummary": "The stream-json library is susceptible to a prototype pollution vulnerability due to improper handling of object keys during JSON parsing. This flaw allows an attacker to inject properties into the Object.prototype by crafting specific input containing the __proto__ key.\nThe vulnerability affects versions of stream-json prior to 3.6.0. It occurs within the Assembler component, which materializes object properties using direct assignment without validating keys against reserved prototype-modifying identifiers.\nBy manipulating the prototype, an attacker can influence application logic that relies on inherited object properties, potentially leading to unauthorized feature activation or broken access control decisions. While the maintainer argues that the attack vector is restricted to local data (such as exports or logs), the exploitation of this vulnerability in environments where untrusted JSON is processed as part of the application contract presents a significant risk to data integrity and security logic.\nThere is no requirement for specific authentication to trigger this vulnerability, as it is a direct consequence of the parsing logic. Successful exploitation requires an attacker to successfully inject a malicious payload into the input stream consumed by the vulnerable library.",
  "technicalDetails": "The vulnerability resides in the Assembler component of the stream-json library, specifically in the logic used to materialize object properties. When the library parses JSON input, it iterates through keys and assigns values to the target object using standard JavaScript assignment syntax. This mechanism fails to account for the special nature of the __proto__ property in JavaScript objects.\nIn the vulnerable versions prior to 3.6.0, the Assembler performs a direct property assignment: object[key] = value. When the key is equal to '__proto__', the JavaScript engine invokes the inherited setter for the prototype chain rather than creating an 'own' property on the target object. This allows the attacker to reach the Object.prototype directly.\nThe attack flow proceeds as follows: First, the attacker provides a malicious JSON payload containing the '__proto__' key. Second, the Assembler processes this key during the stream parsing phase. Third, because there is no sanitization or key-filtering mechanism in place, the JavaScript engine interprets the assignment as a request to modify the prototype of the object being constructed. This modification affects the global Object.prototype, as all objects inherit from this prototype by default in the execution context.\nThe impact of this pollution is significant for applications that perform logic based on inherited properties. For example, if an application checks for the existence of a configuration flag or an authorization role that should be absent on a default object, an attacker can 'pollute' the prototype to ensure that the flag or role is present or set to a specific value. This can bypass authorization checks or alter the state of application-level features.\nFurthermore, injecting a null prototype into objects can lead to runtime exceptions in code that expects standard Object.prototype methods (e.g., toString(), hasOwnProperty()) to be available. While the maintainer notes that the scope is limited to local dumps or logs, any application consuming these files or streams via stream-json is inherently at risk if the content origin is not strictly trusted. The vulnerability is effectively a bypass of object property encapsulation, occurring exclusively within the data processing phase of the library."
}
CVE-2026-104183: stream-json Prototype Pollution Vulnerability (MEDIUM Severity, CVSS: 5.1) | Sceawere