Threadlinqs IntelligenceStart free

Weakness · VariantCWE-1321

CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

KEV-linkedVariant

As of 2026-10-05, CWE-1321 (Prototype Pollution) underlies 5 CVEs tracked by Threadlinqs, 1 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 5 tracked threats.

CVEs
5Mapped to CWE-1321
CISA KEV
1Exploited in the wild
Critical
1CVSS v3 critical CVEs
Threats
5Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-1321?

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

CWE-1321 is a variant-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: JavaScript.

Source: MITRE CWE (CWE-1321 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Confidentiality, Integrity, Availability — Read Application Data, Modify Application Data. This weakness is usually exploited by using a special attribute of objects called proto, constructor, or prototype. Such attributes give access to the object prototype. An attacker can inject attributes that are used in other components by adding or modifying attributes of an object prototype. This creates attributes that exist on every object, or replace critical attributes with malicious ones. This can be problematic if the product depends on existence or non-existence of certain attributes…
  • Availability — DoS: Crash, Exit, or Restart. An attacker can override existing attributes with ones that have incompatible type, which may lead to a crash.

Source: MITRE CWE, common consequences.

How CWE-1321 is exploited in the wild

Threadlinqs maps 5 CVEs to CWE-1321, published between 2026-04-13 and 2026-07-18. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 1 critical, 4 medium. The highest EPSS score in the set is 9.8% (CVE-2026-34621), the modelled probability of exploitation in the next 30 days. 5 tracked threats reference CWE-1321 directly or through a CVE it covers; the most recent is “CVE-2026-4800: Lodash `_.template` Arbitrary Code Injection — Broken 4.18.0 Patch Exposes Supply-Chain Patch-Pinning Risk” (2026-08-26). Affected products concentrate in Adobe (1), CartoDB (1), Hono (1), among 5 vendors in total.

Vulnerabilities (CVEs)

All 5 CVEs mapped to CWE-1321, CISA KEV first, then by CVSS score.

  • CVE-2026-34621 — CISA KEV · CVSS 9.8 critical · EPSS 9.8% · published 2026-04-13
  • CVE-2026-16151 — CVSS 6.3 medium · EPSS 0.3% · published 2026-07-18
  • CVE-2026-16150 — CVSS 6.3 medium · EPSS 0.2% · published 2026-07-18
  • CVE-2026-56763 — CVSS 4.8 medium · EPSS 0.1% · published 2026-07-11
  • CVE-2026-15607 — CVSS 4.3 medium · EPSS 0.2% · published 2026-07-13

Affected vendors

  • Adobe — 1 CVE
  • CartoDB — 1 CVE
  • Hono — 1 CVE
  • RobinHerbots — 1 CVE
  • tanstack — 1 CVE

Threat activity

5 tracked threats cite CWE-1321:

Mitigations

  • Implementation: By freezing the object prototype first (for example, Object.freeze(Object.prototype)), modification of the prototype becomes impossible.
  • Architecture and Design: By blocking modifications of attributes that resolve to object prototype, such as proto or prototype, this weakness can be mitigated.
  • Implementation / Input Validation: When handling untrusted objects, validating using a schema can be used.
  • Implementation: By using an object without prototypes (via Object.create(null) ), adding object prototype attributes by accessing the prototype via the special attributes becomes impossible, mitigating this weakness.
  • Implementation: Map can be used instead of objects in most cases. If Map methods are used instead of object attributes, it is not possible to access the object prototype or modify it.

Source: MITRE CWE, potential mitigations.

Detection methods (MITRE CWE)

  • Automated Static Analysis (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.