Skip to main content

CVE-2026-106550: CWE-1321: Improperly Controlled Modification of Object Prototype Attributes (‘Prototype Pollution’) in Mozilla Node-convict

0
High
VulnerabilityCVE-2026-106550cvecve-2026-106550cwe-1321cwe-915cwe-400
Published: 10/06/2026 (10/06/2026, 20:09:55 UTC)
Source: CVE Database V5
Vendor/Project: Mozilla
Product: Node-convict

Description

Mozilla's Node-convict version 6.2.2 is vulnerable to a prototype pollution flaw in the config.set() function. This vulnerability allows an attacker who can control configuration keys to write arbitrary properties to constructor.<key>, bypassing existing filters. As a result, core JavaScript methods like Object.assign can be overwritten, causing persistent process-wide failures and denial of service until the process is restarted. Exploitation requires an endpoint that forwards attacker-controlled keys into config.set().

Affected software

Mozilla

Node-convict

Affected versions
=6.2.2
node-convict
pkg:npm/node-convict
Affected versions
=6.2.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/06/2026, 20:48:43 UTC

Technical Analysis

The vulnerability in Node-convict 6.2.2 arises from incomplete protections against prototype pollution in the config.set() method. An attacker controlling configuration keys can inject properties into constructor.<key>, which resolves to the global Object function, enabling overwriting of critical JavaScript methods such as Object.assign. Existing filters block constructor.prototype.* and __proto__.*, but do not prevent this attack vector. This leads to persistent denial of service conditions requiring process restarts. Exploitation depends on the presence of an endpoint that forwards attacker-controlled keys into config.set().

Potential Impact

Successful exploitation results in denial of service due to persistent corruption of core JavaScript object methods, causing process-wide failures that require restarting the affected application. This can disrupt availability of services relying on Node-convict 6.2.2.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid forwarding attacker-controlled keys into config.set() or implement strict input validation to prevent prototype pollution via constructor.<key> properties.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
certcc
Date Reserved
2026-10-06T20:07:46.075Z
State
PUBLISHED

Threat ID: 6ac55b392cdf04f656dc28a1

Added to database: 10/06/2026, 20:34:01 UTC

Last enriched: 10/06/2026, 20:48:43 UTC

Last updated: 10/06/2026, 20:49:08 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses