THREAT OPS › Threat News › [NVD] CVE-2026-33228 (CRITICAL 9.8) — flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the internal input buffer is a JavaScript Array, a
[NVD] CVE-2026-33228 (CRITICAL 9.8) — flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the internal input buffer is a JavaScript Array, a
CVE-2026-33228 CVSS: 9.8 CRITICAL Published: 2026-03-20T23:16:46.510
flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the internal input buffer is a JavaScript Array, accessing it with the key "__proto__" returns Array
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-33228cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-33228