Sep 28, 2026·6 min read·3 visits
The scim-patch library fails to restrict traversal through inherited properties during SCIM PATCH operations. Authenticated attackers can use dotted paths or implicit key resolution to access and mutate global built-in methods, leading to prototype pollution and application instability.
A vulnerability in the scim-patch library allows authenticated users to pollute the global JavaScript execution environment. By transmitting a SCIM PATCH operation targeting inherited built-in methods, such as toString, valueOf, or hasOwnProperty, attackers bypass blocklist filters and mutate global prototype objects. This flaw occurs due to the library relying on standard prototype lookup and the 'in' operator during path-resolution and assignment, resolving to shared native functions instead of treating them as missing own-properties.
The vulnerability identified as CVE-2026-61834 is a medium-severity security flaw within the scim-patch library. This NPM package is designed to parse and apply SCIM patch operations according to RFC 7644 specifications. The library failed to restrict modification of inherited built-in methods during path-resolution and assignment routines.\n\nWhile standard prototype pollution vectors targeting explicit keywords like __proto__ or constructor were blocked by a denylist, the traversal logic remained vulnerable to inherited property lookups. An authenticated attacker can target inherited properties such as toString, valueOf, or hasOwnProperty. Because JavaScript resolves these properties through the prototype chain to global built-in functions, the library proceeds to mutate these shared function objects.\n\nThis behavior maps to CWE-915 (Improperly Controlled Modification of Dynamically-Determined Object Attributes) and CWE-1321 (Improperly Controlled Modification of Object Prototype Attributes). The attack surface is exposed via standard SCIM API endpoints that process client-defined patch payloads. Successful exploitation permits process-global mutation of built-in method objects.
The root cause of this vulnerability lies in the reliance on unconstrained property lookups within the path navigation and value assignment implementations of scim-patch. Specifically, the library utilizes the standard bracket lookup operator (schema[subPath]) and the in operator (key in obj) to verify the existence of intermediate nodes during path resolution.\n\nIn JavaScript, both of these operations evaluate properties across the entire prototype chain of the object. When a SCIM patch path segment specifies a built-in method like toString, the expression schema['toString'] evaluates to the native Function.prototype.toString or Object.prototype.toString object. Since the expression returns a truthy value, the library incorrectly assumes that the path segment represents an already initialized local property.\n\nThe resolver then uses this resolved function object as the context for downstream property writes. When the final assignment takes place, the library appends arbitrary properties directly onto the shared native function object. This behavior compromises the integrity of the execution environment, polluting the global scope and modifying how the application processes object evaluations.
The vulnerable version of the library utilizes unsafe lookup patterns in two critical areas: navigate() and assign(). In the navigate() function, the resolution loop does not check whether a property belongs to the target object itself or if it is inherited from the prototype chain.\n\ntypescript\n// Vulnerable path resolution pattern\nschemas = schemas.flatMap((schema)=>{\n if (!schema[subPath] && options.isRemoveOp)\n throw new InvalidRemoveOpPath();\n\n return schema[subPath] || (schema[subPath] = {});\n});\n\n\nSimilarly, in the assign() function, the existence of intermediate path keys is checked using the in operator. Because in returns true for inherited keys, the check fails to catch native functions like toString, allowing the assignment function to descend into the global function prototype and write the target property onto it.\n\ntypescript\n// Vulnerable assignment pattern\nfor (let i = 0; i < lastKeyIndex; ++ i) {\n const key = keyPath[i];\n if (!(key in obj)){\n obj[key] = {};\n }\n obj = obj[key];\n}\n\n\nThe fix introduced in version 0.9.2 replaces these operations with explicit Object.prototype.hasOwnProperty.call() checks. This modification ensures that any inherited property that does not explicitly exist as an 'own' property of the target object is treated as missing. The library subsequently creates a fresh local object to shadow the inherited name rather than modifying the global built-in.\n\nmermaid\ngraph LR\n subgraph Vulnerable Flow\n A["Path Segment 'toString'"] --> B{"schema['toString'] Check"}\n B -->|Resolves to Function.prototype| C["Descend into Global built-in"]\n C --> D["Pollute Global toString Object"]\n end\n subgraph Patched Flow\n E["Path Segment 'toString'"] --> F{"hasOwnProperty('toString') Check"}\n F -->|False| G["Create Local Object {}"]\n G --> H["Shadow inherited property safely"]\n end\n
Exploitation of CVE-2026-61834 requires the ability to send authenticated SCIM PATCH requests to an application that processes user or group attributes using the scim-patch package. The attack can be initiated through two distinct payload structures: dotted path notation and implicit path resolution via the value payload.\n\nIn the dotted path vector, an attacker includes a target path that references a built-in method followed by a custom attribute name, such as toString.polluted. The parsing engine processes the first segment (toString), resolves it to the global prototype, and appends the second segment (polluted) with the provided value directly onto the native function.\n\njson\n[\n {\n "op": "add",\n "path": "toString.pollutedAttribute",\n "value": "polluted"\n }\n]\n\n\nIn the alternative vector, where no path is explicitly defined, the attacker can leverage the keys of the value object. The assignment engine processes each key, performing the same unsafe in check on keys such as toString.nestedValue. This achieves an identical result, polluting the runtime environment.\n\njson\n[\n {\n "op": "add",\n "value": {\n "toString.implicitPolluted": "polluted"\n }\n }\n]\n
The impact of this vulnerability is characterized by a process-global integrity compromise. Although mutating built-in methods does not immediately expose sensitive data, it destabilizes the JavaScript execution environment. This can cause downstream application libraries or frameworks to crash, leading to a Denial of Service.\n\nFurthermore, prototype pollution of this nature can lead to secondary vulnerabilities. If downstream application logic evaluates properties on native objects without performing safety checks, an attacker may exploit this behavior to execute arbitrary code or bypass security controls. This is particularly critical in authentication modules, authorization checks, and logging utilities that invoke native methods such as toString() during processing.\n\nThe CVSS 3.1 score is calculated as 4.3 (Medium), reflecting a network-based attack vector with low complexity and low integrity impact, but requiring low-privileged user authentication. The impact on confidentiality and availability is rated as none under the base vector, although secondary exploitation could elevate these impacts depending on application context.
The primary remediation strategy is upgrading the scim-patch library to version 0.9.2 or higher. The patch incorporates explicit own-property checks, preventing the traversal engine from resolving inherited built-in methods as valid path structures.\n\nFor environments where immediate patching is not feasible, several defensive-in-depth measures can be deployed to reduce exposure. Network-level mitigations include configuring Web Application Firewalls (WAFs) to inspect incoming SCIM PATCH payloads and reject requests containing path segments matching known built-in method names.\n\nAdditionally, developers can freeze native prototype objects at application startup to prevent any modifications from taking place:\n\njavascript\n// Freeze built-in prototypes to block pollution\nObject.freeze(Object.prototype);\nObject.freeze(Function.prototype);\n
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N| Product | Affected Versions | Fixed Version |
|---|---|---|
scim-patch thomaspoignant | < 0.9.2 | 0.9.2 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-915 / CWE-1321 |
| Attack Vector | Network |
| CVSS v3.1 Score | 4.3 (Medium) |
| EPSS Score | 0.0028 (0.28%) |
| Impact | Process-Global Attribute Mutation |
| Exploit Status | Proof-of-Concept |
| KEV Status | Not Listed |
The product allows an attacker to modify properties of the global object prototype, which can affect behavior of all objects that inherit from that prototype.
An OS command injection vulnerability in the grep_search tool of the code-ollama package allows remote code execution. This vulnerability is triggered when a local client executes the CLI against a malicious or compromised Ollama server. Due to grep_search being classified as a read-only tool, the CLI executes it automatically in Plan mode without human-in-the-loop validation, leading to zero-interaction local system compromise.
On September 16, 2026, Cisco disclosed a critical authentication bypass vulnerability affecting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). This vulnerability allows unauthenticated, remote attackers to bypass the administrative interface controls and execute privileged API requests. Due to active exploitation in the wild, the Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to the Known Exploited Vulnerabilities (KEV) Catalog with an immediate remediation deadline.
containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph can force very high CPU/memory usage during PullImage (before container start), causing long ContainerCreating stalls and, at larger sizes, node/runtime instability. The vulnerability occurs because containerd's image-pull descriptor graph resolution handlers processed OCI image indices and manifests recursively without enforcing boundaries on traversal depth or breadth, and without maintaining a global visited registry to count duplicate references.
An unauthenticated path traversal vulnerability exists in the Khoj AI assistant platform via the static file serving endpoint `/home/{file_path:path}`. Due to improper path sanitization when handling user input with Python's pathlib module, a remote attacker can read arbitrary files from the server's filesystem.
An argument injection vulnerability (CWE-88) in CliInvoke and AlastairLundy.CliInvoke allows local attackers to execute arbitrary system commands. By injecting double-quote characters into target file paths or arguments, attackers can terminate operating-system-level quoted boundaries and introduce new commands when shell runners are utilized.
An OS command injection vulnerability exists in the PowerShell and Cmd shell wrappers of the CliInvoke .NET library (specifically the CliInvoke.Specializations package). Under vulnerable configurations, arguments and targets are passed as a single flat string to ProcessStartInfo.Arguments, permitting double-quote breakout and execution of arbitrary secondary commands with host process privileges.