THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-325j-mg25-8q58 (critical) — yayson: Prototype pollution in Store/LegacyStore deserialization

[GHSA] GHSA-325j-mg25-8q58 (critical) — yayson: Prototype pollution in Store/LegacyStore deserialization

medgithub_advisoriesPublished 2026-09-11

GHSA-325j-mg25-8q58 Severity: critical CVE: CVE-2026-61534

yayson: Prototype pollution in Store/LegacyStore deserialization

# Summary `Store`/`LegacyStore` key internal lookup tables by the `type`, `id`, and relationship names from a JSON:API document. Because these were plain objects, a document with `type: "__proto__"` writes onto `Object.prototype`, polluting every object in the process.

# S

Indicators of compromise

Original source: https://github.com/advisories/GHSA-325j-mg25-8q58