DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-61834: CVE-2026-61834: Prototype Pollution and Mutation of Inherited Built-in Method Objects in scim-patch

CVE-2026-61834: Prototype Pollution and Mutation of Inherited Built-in Method Objects in scim-patch

Vulnerability ID: CVE-2026-61834
CVSS Score: 4.3
Published: 2026-09-28

A vulnerability in the scim-patch library allows authenticated users to pollute the global JavaScript execution environment. By transmitting a SCIM PATCH operation targeting inherited built-in methods, such as toString, valueOf, or hasOwnProperty, attackers bypass blocklist filters and mutate global prototype objects. This flaw occurs due to the library relying on standard prototype lookup and the 'in' operator during path-resolution and assignment, resolving to shared native functions instead of treating them as missing own-properties.

TL;DR

The scim-patch library fails to restrict traversal through inherited properties during SCIM PATCH operations. Authenticated attackers can use dotted paths or implicit key resolution to access and mutate global built-in methods, leading to prototype pollution and application instability.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-915 / CWE-1321
  • Attack Vector: Network
  • CVSS v3.1 Score: 4.3 (Medium)
  • EPSS Score: 0.0028 (0.28%)
  • Impact: Process-Global Attribute Mutation
  • Exploit Status: Proof-of-Concept
  • KEV Status: Not Listed

Affected Systems

  • scim-patch NPM Package
  • scim-patch: < 0.9.2 (Fixed in: 0.9.2)

Code Analysis

Commit: c86474f

Fix prototype pollution/mutation of inherited built-in method objects

@@ -368,10 +368,17 @@ function navigate(inputSchema: any, paths: string[], options: NavigateOptions =
             });
         } else {
             schemas = schemas.flatMap((schema)=>{
-                if (!schema[subPath] && options.isRemoveOp)
+                const existing = (schema != null && Object.prototype.hasOwnProperty.call(schema, subPath))
+                    ? schema[subPath]
+                    : undefined;
+                if (!existing && options.isRemoveOp)
                     throw new InvalidRemoveOpPath();

-                return schema[subPath] || (schema[subPath] = {});
+                return existing || (schema[subPath] = {});
             });
         }
     }
@@ -448,7 +455,10 @@ function assign(obj:any, keyPath:Array<string>, value:any, op: string) {
     const lastKeyIndex = keyPath.length-1;
     for (let i = 0; i < lastKeyIndex; ++ i) {
         const key = keyPath[i];
-        if (!(key in obj)){
+        if (!Object.prototype.hasOwnProperty.call(obj, key)){
             obj[key] = {};
         }
         obj = obj[key];
Enter fullscreen mode Exit fullscreen mode

Exploit Details

Mitigation Strategies

  • Upgrade scim-patch dependency to version 0.9.2 or above.
  • Implement Web Application Firewall rules to block payloads containing dot-notated built-in methods in the path parameter.
  • Freeze the prototypes of standard built-in objects at runtime startup.

Remediation Steps:

  1. Identify vulnerable installations of scim-patch using npm list scim-patch or yarn why scim-patch.
  2. Update package.json to point to scim-patch version ^0.9.2.
  3. Run npm install or yarn install to apply the dependency update.
  4. Verify the fix by running integration tests with custom payloads targeting toString, valueOf, and hasOwnProperty.

References


Read the full report for CVE-2026-61834 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)