msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, constructing msgpack5 with an empty or partial options object disables the default protoAction: 'error' protection. A decoded map containing a __proto__ key can then replace the decoded object's prototype, potentially changing inherited properties or downstream behavior, although Object.prototype is not modified globally. This issue is fixed in version 6.1.0.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8hq7-ggx2-cc6m | msgpack5: Partial options disable prototype protection |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, constructing msgpack5 with an empty or partial options object disables the default protoAction: 'error' protection. A decoded map containing a __proto__ key can then replace the decoded object's prototype, potentially changing inherited properties or downstream behavior, although Object.prototype is not modified globally. This issue is fixed in version 6.1.0. | |
| Title | msgpack5: Partial options disable prototype protection | |
| Weaknesses | CWE-1321 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-08T17:13:00.613Z
Reserved: 2026-10-07T15:53:23.587Z
Link: CVE-2026-107301
No data.
Status : Received
Published: 2026-10-08T17:17:16.143
Modified: 2026-10-08T17:17:16.143
Link: CVE-2026-107301
No data.
OpenCVE Enrichment
Updated: 2026-10-08T19:00:07Z
Weaknesses
Github GHSA