THREAT OPS › Threat News › [GHSA] GHSA-5957-5c94-3v7w (medium) — Jodit has prototype pollution via Jodit.configure() / ConfigMerge
[GHSA] GHSA-5957-5c94-3v7w (medium) — Jodit has prototype pollution via Jodit.configure() / ConfigMerge
GHSA-5957-5c94-3v7w Severity: medium CVE: CVE-2026-54756
Jodit has prototype pollution via Jodit.configure() / ConfigMerge
### Summary `Jodit.configure(options)` — and the internal `ConfigMerge` / `ConfigProto` helpers — merged user-supplied options into the editor configuration without filtering prototype-mutating keys. A payload nested under an existing plain-object option such as `controls` c
Indicators of compromise
- CVE-2026-54756cve
Original source: https://github.com/advisories/GHSA-5957-5c94-3v7w