The Weakest Link: Popular Node.js Config Library “Convict” Hit by Prototype Pollution
ID: 498cb9a6-021c-5e53-a855-d70fde951ab1
STIX ID: report--498cb9a6-021c-5e53-a855-d70fde951ab1
Feed Name: securityonline.info
Threat Score
A critical prototype pollution vulnerability (CVE-2026-33864, CVSS 9.4) was found in the node-convict configuration library (<= 6.2.4). By tampering with String.prototype to defeat a startsWith() check, an attacker can use convict.set to inject properties into Object.prototype, risking authentication bypass, denial of service, or remote code execution; maintainers released version 6.2.5 to patch the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
