CVE-2026-55886: CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in xdan jodit
A prototype pollution vulnerability exists in the xdan jodit package versions prior to 4.12.26. The vulnerability arises from the Jodit.modules.Helpers.set() function, which improperly allows modification of Object.prototype via specially crafted key paths containing __proto__, constructor, or prototype. This can lead to unexpected property injection and potential security issues. The vulnerability is fixed in version 4.12.26 by rejecting such prototype-mutating keys.
AI Analysis
Technical Summary
The vulnerability (CVE-2026-55886) in xdan jodit's Jodit.modules.Helpers.set(chain, value, obj) method allows prototype pollution by walking a dot-separated key path without filtering out keys that mutate Object.prototype, such as __proto__, constructor, or prototype. This enables an attacker to inject or modify properties on Object.prototype, potentially causing logic bypass, denial of service, or other secondary security impacts. The issue affects all versions prior to 4.12.26. The fix implemented in 4.12.26 rejects any chain segments that include these prototype-mutating keys, preventing the pollution.
Potential Impact
Applications using vulnerable versions of jodit that pass user-controlled or partially user-controlled key paths to Jodit.modules.Helpers.set() may be exposed to prototype pollution. This can result in unexpected property injection on Object.prototype, which may lead to logic bypass, denial of service, or other security issues depending on how the polluted properties are used within the application.
Mitigation Recommendations
A patch is available in jodit version 4.12.26 that addresses this vulnerability by rejecting any key paths containing __proto__, constructor, or prototype segments. Users should upgrade to version 4.12.26 or later to remediate this issue. No additional mitigation is required if the upgrade is applied.
CVE-2026-55886: CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in xdan jodit
Description
A prototype pollution vulnerability exists in the xdan jodit package versions prior to 4.12.26. The vulnerability arises from the Jodit.modules.Helpers.set() function, which improperly allows modification of Object.prototype via specially crafted key paths containing __proto__, constructor, or prototype. This can lead to unexpected property injection and potential security issues. The vulnerability is fixed in version 4.12.26 by rejecting such prototype-mutating keys.
CVSS v4.0
Score 6.3medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability (CVE-2026-55886) in xdan jodit's Jodit.modules.Helpers.set(chain, value, obj) method allows prototype pollution by walking a dot-separated key path without filtering out keys that mutate Object.prototype, such as __proto__, constructor, or prototype. This enables an attacker to inject or modify properties on Object.prototype, potentially causing logic bypass, denial of service, or other secondary security impacts. The issue affects all versions prior to 4.12.26. The fix implemented in 4.12.26 rejects any chain segments that include these prototype-mutating keys, preventing the pollution.
Potential Impact
Applications using vulnerable versions of jodit that pass user-controlled or partially user-controlled key paths to Jodit.modules.Helpers.set() may be exposed to prototype pollution. This can result in unexpected property injection on Object.prototype, which may lead to logic bypass, denial of service, or other security issues depending on how the polluted properties are used within the application.
Mitigation Recommendations
A patch is available in jodit version 4.12.26 that addresses this vulnerability by rejecting any key paths containing __proto__, constructor, or prototype segments. Users should upgrade to version 4.12.26 or later to remediate this issue. No additional mitigation is required if the upgrade is applied.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-17T16:59:42.760Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a457a6627e9c79719197541
Added to database: 07/01/2026, 20:36:54 UTC
Last enriched: 07/31/2026, 21:33:21 UTC
Last updated: 08/14/2026, 00:41:13 UTC
Views: 78
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.