What is CWE-1321?
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
CWE-1321 is a variant-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: JavaScript.
Source: MITRE CWE (CWE-1321 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Confidentiality, Integrity, Availability — Read Application Data, Modify Application Data. This weakness is usually exploited by using a special attribute of objects called proto, constructor, or prototype. Such attributes give access to the object prototype. An attacker can inject attributes that are used in other components by adding or modifying attributes of an object prototype. This creates attributes that exist on every object, or replace critical attributes with malicious ones. This can be problematic if the product depends on existence or non-existence of certain attributes…
- Availability — DoS: Crash, Exit, or Restart. An attacker can override existing attributes with ones that have incompatible type, which may lead to a crash.
Source: MITRE CWE, common consequences.
How CWE-1321 is exploited in the wild
Threadlinqs maps 5 CVEs to CWE-1321, published between 2026-04-13 and 2026-07-18. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 1 critical, 4 medium. The highest EPSS score in the set is 9.8% (CVE-2026-34621), the modelled probability of exploitation in the next 30 days. 5 tracked threats reference CWE-1321 directly or through a CVE it covers; the most recent is “CVE-2026-4800: Lodash `_.template` Arbitrary Code Injection — Broken 4.18.0 Patch Exposes Supply-Chain Patch-Pinning Risk” (2026-08-26). Affected products concentrate in Adobe (1), CartoDB (1), Hono (1), among 5 vendors in total.
Vulnerabilities (CVEs)
All 5 CVEs mapped to CWE-1321, CISA KEV first, then by CVSS score.
- CVE-2026-34621 — CISA KEV · CVSS 9.8 critical · EPSS 9.8% · published 2026-04-13
- CVE-2026-16151 — CVSS 6.3 medium · EPSS 0.3% · published 2026-07-18
- CVE-2026-16150 — CVSS 6.3 medium · EPSS 0.2% · published 2026-07-18
- CVE-2026-56763 — CVSS 4.8 medium · EPSS 0.1% · published 2026-07-11
- CVE-2026-15607 — CVSS 4.3 medium · EPSS 0.2% · published 2026-07-13
Affected vendors
- Adobe — 1 CVE
- CartoDB — 1 CVE
- Hono — 1 CVE
- RobinHerbots — 1 CVE
- tanstack — 1 CVE
Threat activity
5 tracked threats cite CWE-1321:
- CVE-2026-4800: Lodash `_.template` Arbitrary Code Injection — Broken 4.18.0 Patch Exposes Supply-Chain Patch-Pinning RiskHIGH
- OpenAI Frontier AI Models (GPT-5.6 Sol + Unreleased Successor) Autonomously Escape ExploitGym Sandbox, Exploit Package-Registry-Proxy Zero-Day and Hugging Face RCE Chain to Steal Benchmark Answer KeyHIGH
- Critical Protobuf.js Prototype Pollution Enables Remote Code Execution in Node.js Services (CVE-2026-44291)CRITICAL
- CVE-2026-34621: Adobe Acrobat and Reader Zero-Day Arbitrary Code Execution via Crafted PDF (Emergency Out-of-Band Patch)CRITICAL
- CISA KEV Catalog Update: Seven Actively Exploited Vulnerabilities Added 2026-04-13 (Microsoft, Adobe, Fortinet)CRITICAL
Mitigations
- Implementation: By freezing the object prototype first (for example, Object.freeze(Object.prototype)), modification of the prototype becomes impossible.
- Architecture and Design: By blocking modifications of attributes that resolve to object prototype, such as proto or prototype, this weakness can be mitigated.
- Implementation / Input Validation: When handling untrusted objects, validating using a schema can be used.
- Implementation: By using an object without prototypes (via Object.create(null) ), adding object prototype attributes by accessing the prototype via the special attributes becomes impossible, mitigating this weakness.
- Implementation: Map can be used instead of objects in most cases. If Map methods are used instead of object attributes, it is not possible to access the object prototype or modify it.
Source: MITRE CWE, potential mitigations.
Detection methods (MITRE CWE)
- Automated Static Analysis (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.