THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-5957-5c94-3v7w (medium) — Jodit has prototype pollution via Jodit.configure() / ConfigMerge

[GHSA] GHSA-5957-5c94-3v7w (medium) — Jodit has prototype pollution via Jodit.configure() / ConfigMerge

medgithub_advisoriesPublished 2026-07-31

GHSA-5957-5c94-3v7w Severity: medium CVE: CVE-2026-54756

Jodit has prototype pollution via Jodit.configure() / ConfigMerge

### Summary `Jodit.configure(options)` — and the internal `ConfigMerge` / `ConfigProto` helpers — merged user-supplied options into the editor configuration without filtering prototype-mutating keys. A payload nested under an existing plain-object option such as `controls` c

Indicators of compromise

Original source: https://github.com/advisories/GHSA-5957-5c94-3v7w