CVE-2026-61834: Prototype Pollution and Mutation of Inherited Built-in Method Objects in scim-patch
Vulnerability ID: CVE-2026-61834
CVSS Score: 4.3
Published: 2026-09-28
A vulnerability in the scim-patch library allows authenticated users to pollute the global JavaScript execution environment. By transmitting a SCIM PATCH operation targeting inherited built-in methods, such as toString, valueOf, or hasOwnProperty, attackers bypass blocklist filters and mutate global prototype objects. This flaw occurs due to the library relying on standard prototype lookup and the 'in' operator during path-resolution and assignment, resolving to shared native functions instead of treating them as missing own-properties.
TL;DR
The scim-patch library fails to restrict traversal through inherited properties during SCIM PATCH operations. Authenticated attackers can use dotted paths or implicit key resolution to access and mutate global built-in methods, leading to prototype pollution and application instability.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-915 / CWE-1321
- Attack Vector: Network
- CVSS v3.1 Score: 4.3 (Medium)
- EPSS Score: 0.0028 (0.28%)
- Impact: Process-Global Attribute Mutation
- Exploit Status: Proof-of-Concept
- KEV Status: Not Listed
Affected Systems
- scim-patch NPM Package
-
scim-patch: < 0.9.2 (Fixed in:
0.9.2)
Code Analysis
Commit: c86474f
Fix prototype pollution/mutation of inherited built-in method objects
@@ -368,10 +368,17 @@ function navigate(inputSchema: any, paths: string[], options: NavigateOptions =
});
} else {
schemas = schemas.flatMap((schema)=>{
- if (!schema[subPath] && options.isRemoveOp)
+ const existing = (schema != null && Object.prototype.hasOwnProperty.call(schema, subPath))
+ ? schema[subPath]
+ : undefined;
+ if (!existing && options.isRemoveOp)
throw new InvalidRemoveOpPath();
- return schema[subPath] || (schema[subPath] = {});
+ return existing || (schema[subPath] = {});
});
}
}
@@ -448,7 +455,10 @@ function assign(obj:any, keyPath:Array<string>, value:any, op: string) {
const lastKeyIndex = keyPath.length-1;
for (let i = 0; i < lastKeyIndex; ++ i) {
const key = keyPath[i];
- if (!(key in obj)){
+ if (!Object.prototype.hasOwnProperty.call(obj, key)){
obj[key] = {};
}
obj = obj[key];
Exploit Details
- GitHub Security Advisory: Advisory details describing the vulnerability mechanics and remediation paths.
Mitigation Strategies
- Upgrade scim-patch dependency to version 0.9.2 or above.
- Implement Web Application Firewall rules to block payloads containing dot-notated built-in methods in the path parameter.
- Freeze the prototypes of standard built-in objects at runtime startup.
Remediation Steps:
- Identify vulnerable installations of scim-patch using npm list scim-patch or yarn why scim-patch.
- Update package.json to point to scim-patch version ^0.9.2.
- Run npm install or yarn install to apply the dependency update.
- Verify the fix by running integration tests with custom payloads targeting toString, valueOf, and hasOwnProperty.
References
- GitHub Security Advisory GHSA-2mhw-wcx5-v3xj
- GitHub Pull Request #1127
- GitHub Commit c86474f
- Release v0.9.2
- National Vulnerability Database (NVD)
- CVE.org Authority Record
- Shodan Vulnerability Details
- MITRE ATT&CK Mapping Portal
Read the full report for CVE-2026-61834 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)