CVE-2026-107301

medium

Description

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, constructing msgpack5 with an empty or partial options object disables the default protoAction: 'error' protection. A decoded map containing a __proto__ key can then replace the decoded object's prototype, potentially changing inherited properties or downstream behavior, although Object.prototype is not modified globally. This issue is fixed in version 6.1.0.

References

https://github.com/mcollina/msgpack5/security/advisories/GHSA-8hq7-ggx2-cc6m

https://github.com/mcollina/msgpack5/releases/tag/v6.1.0

https://github.com/mcollina/msgpack5/commit/20e82600ac9462e679c8a45e5723315f21e2c774

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-95112

Details

Source: Mitre, NVD

Published: 2026-10-08

Updated: 2026-10-08

Risk Information

CVSS v2

Base Score: 6.1

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:C/A:P

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L

Severity: Medium

EPSS

EPSS: 0.00366