<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 18:46:46 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-368263</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-368263</link>
      <description>EUVD-2026-368263</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-368263</guid>
    </item>
    <item>
      <title>fkie_cve-2026-55091</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55091</link>
      <description>&lt;p&gt;flat-to-nested converts a hierarchy from a flat representation to a nested representation. Prior to 1.1.2, FlatToNested.prototype.convert in index.js uses attacker-influenced id and parent record fields directly as keys in the plain temp and pendingChildOf objects. When parent or id is __proto__, temp[parent] can resolve to Object.prototype, and initPush() can write attacker-controlled data to the global children prototype property while existing prototype methods remain intact. Any application that passes attacker-influenced flat records to convert() can therefore expose unrelated objects to polluted inherited state, causing application-logic corruption or denial of service and potentially enabling greater impact when a downstream prototype-pollution gadget is present. The constructor and prototype strings are also unsafe inherited-key values in the same lookup design. This issue is fixed in version 1.1.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;flat-to-nested converts a hierarchy from a flat representation to a nested representation. Prior to 1.1.2, FlatToNested.prototype.convert in index.js uses attacker-influenced id and parent record fields directly as keys in the plain temp and pendingChildOf objects. When parent or id is __proto__, temp[parent] can resolve to Object.prototype, and initPush() can write attacker-controlled data to the global children prototype property while existing prototype methods remain intact. Any application that passes attacker-influenced flat records to convert() can therefore expose unrelated objects to polluted inherited state, causing application-logic corruption or denial of service and potentially enabling greater impact when a downstream prototype-pollution gadget is present. The constructor and prototype strings are also unsafe inherited-key values in the same lookup design. This issue is fixed in version 1.1.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-55091</guid>
    </item>
    <item>
      <title>GHSA-hp36-v28f-w3r4 — flat-to-nested: Prototype pollution in flat-to-nested convert() via __proto__ parent/id key</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hp36-v28f-w3r4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: flat-to-nested&lt;/p&gt;
&lt;p&gt;### Summary
  `convert()` builds the nested tree by using each flat record&amp;#39;s `id` and `parent` field values directly as object keys, with no guard against `__proto__` / `constructor` / `prototype`. A record whose `parent` is the string `&amp;#34;__proto__&amp;#34;` makes `temp[parent]` resolve to `Object.prototype`, and the following `initPush(...)` writes attacker-controlled data onto the global prototype. Any application that passes attacker-influenced records to `convert()` is affected, and the base prototype methods stay intact so the pollution is stealthy.&lt;/p&gt;
&lt;p&gt;### Details
  In `index.js`, `convert()` (`FlatToNested.prototype.convert`):&lt;/p&gt;
&lt;p&gt;- `temp = {}` (line 45) and `pendingChildOf = {}` (line 46) are plain objects, so they inherit from `Object.prototype`.
  - For each record, `parent = flatEl[this.config.parent]` (line 51) is taken verbatim from input.
  - Line 57: `if (temp[parent] !== undefined)` — when `parent === &amp;#34;__proto__&amp;#34;`, `temp[&amp;#34;__proto__&amp;#34;]` resolves via the prototype chain to `Object.prototype`, which is `!== undefined`, so the
  branch is taken.
  - Line 59: `initPush(this.config.children, temp[parent], flatEl)` → effectively `initPush(&amp;#34;children&amp;#34;, Object.prototype, flatEl)`.
  - `initPush` (lines 4-9): `Object.prototype[&amp;#34;children&amp;#34;] = []` then `Object.prototype[&amp;#34;children&amp;#34;].push(flatEl)` — **attacker-controlled data is written onto the global `Object.prototype`.**&lt;/p&gt;
&lt;p&gt;There is no sanitization of `id` / `parent` anywhere; they flow straight into `temp[id]`, `temp[parent]`, and `…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: flat-to-nested&lt;/p&gt;
&lt;p&gt;### Summary
  `convert()` builds the nested tree by using each flat record&amp;#39;s `id` and `parent` field values directly as object keys, with no guard against `__proto__` / `constructor` / `prototype`. A record whose `parent` is the string `&amp;#34;__proto__&amp;#34;` makes `temp[parent]` resolve to `Object.prototype`, and the following `initPush(...)` writes attacker-controlled data onto the global prototype. Any application that passes attacker-influenced records to `convert()` is affected, and the base prototype methods stay intact so the pollution is stealthy.&lt;/p&gt;
&lt;p&gt;### Details
  In `index.js`, `convert()` (`FlatToNested.prototype.convert`):&lt;/p&gt;
&lt;p&gt;- `temp = {}` (line 45) and `pendingChildOf = {}` (line 46) are plain objects, so they inherit from `Object.prototype`.
  - For each record, `parent = flatEl[this.config.parent]` (line 51) is taken verbatim from input.
  - Line 57: `if (temp[parent] !== undefined)` — when `parent === &amp;#34;__proto__&amp;#34;`, `temp[&amp;#34;__proto__&amp;#34;]` resolves via the prototype chain to `Object.prototype`, which is `!== undefined`, so the
  branch is taken.
  - Line 59: `initPush(this.config.children, temp[parent], flatEl)` → effectively `initPush(&amp;#34;children&amp;#34;, Object.prototype, flatEl)`.
  - `initPush` (lines 4-9): `Object.prototype[&amp;#34;children&amp;#34;] = []` then `Object.prototype[&amp;#34;children&amp;#34;].push(flatEl)` — **attacker-controlled data is written onto the global `Object.prototype`.**&lt;/p&gt;
&lt;p&gt;There is no sanitization of `id` / `parent` anywhere; they flow straight into `temp[id]`, `temp[parent]`, and `…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hp36-v28f-w3r4</guid>
    </item>
  </channel>
</rss>
