CVE WATCH / VULNERABILITY DETAIL
CVE-2026-107353
MEDIUMCVSS 6.5NVD feed
Published 7 October 2026 · tracked since 8 October 2026
Description
traverse (npm) versions 0.3.6 through 0.3.9, 0.4.0 through 0.4.6, 0.5.0 through 0.5.2, and 0.6.0 through 0.6.11 allow prototype pollution through set(). When the path passed to set() crosses a primitive value, the next path segment is resolved on that primitive's built-in prototype, so an applicatio
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-76266 HIGH 7.7
- CVE-2026-1403 MEDIUM 6.5
- CVE-2026-107229 MEDIUM 4
- CVE-2026-107161 HIGH 7.5
- CVE-2026-107313 MEDIUM 4.2
- CVE-2026-103371
- CVE-2026-107215 HIGH 7.5
- CVE-2026-107211
- CVE-2026-95606 CRITICAL 9.8
- CVE-2026-95534 HIGH 8.8