Executive brief
IBM Instana is a monitoring tool used to observe and manage the performance of enterprise applications. A security vulnerability in its Node.js monitoring component could allow an attacker to interfere with the application's internal logic or cause it to crash. This could lead to inaccurate monitoring data, service disruptions, or unauthorized changes to how the application behaves.
Technical details
A prototype pollution vulnerability exists in the IBM Instana Node.js tracer component (@instana/core) version 6.2.1. The flaw is located within the configuration normalization API, where improper validation allows for the modification of object prototypes. An attacker with local access could exploit this to inject properties into the global Object prototype, potentially leading to denial of service, data manipulation, or in some cases, remote code execution depending on the application environment. The issue is addressed in Instana Agent container image build 1.0.321.
Affected products
- IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320
- IBM @instana/core 6.2.1
Timeline
- 2026-07-28: disclosed
- 2026-07-28: advisory
- 2026-07-28: patched: Fixed in Instana Agent build 1.0.321