THREAT OPS › Threat News › [GHSA] GHSA-325j-mg25-8q58 (critical) — yayson: Prototype pollution in Store/LegacyStore deserialization
[GHSA] GHSA-325j-mg25-8q58 (critical) — yayson: Prototype pollution in Store/LegacyStore deserialization
GHSA-325j-mg25-8q58 Severity: critical CVE: CVE-2026-61534
yayson: Prototype pollution in Store/LegacyStore deserialization
# Summary `Store`/`LegacyStore` key internal lookup tables by the `type`, `id`, and relationship names from a JSON:API document. Because these were plain objects, a document with `type: "__proto__"` writes onto `Object.prototype`, polluting every object in the process.
# S
Indicators of compromise
- CVE-2026-61534cve
Original source: https://github.com/advisories/GHSA-325j-mg25-8q58