logo

The Weakest Link: Popular Node.js Config Library “Convict” Hit by Prototype Pollution

ID: 498cb9a6-021c-5e53-a855-d70fde951ab1

STIX ID: report--498cb9a6-021c-5e53-a855-d70fde951ab1

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-30

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical prototype pollution vulnerability (CVE-2026-33864, CVSS 9.4) was found in the node-convict configuration library (<= 6.2.4). By tampering with String.prototype to defeat a startsWith() check, an attacker can use convict.set to inject properties into Object.prototype, risking authentication bypass, denial of service, or remote code execution; maintainers released version 6.2.5 to patch the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.