Executive brief
RobinHerbots Inputmask is a popular JavaScript library used to create input masks for form fields, ensuring users enter data in a specific format (like phone numbers or dates). A vulnerability in how the library merges configuration settings allows an attacker to inject malicious properties into the application's core JavaScript objects. This can lead to application crashes, logic errors, or unauthorized changes to how the website behaves for other users.
Technical details
A prototype pollution vulnerability exists in RobinHerbots Inputmask up to version 5.0.9. The issue is located within the internal deep merge helper in `lib/dependencyLibs/extend.js`, which is utilized by public functions including `extendDefaults`, `extendDefinitions`, and `extendAliases`. The merge logic fails to sanitize sensitive keys such as `__proto__`, allowing a remote attacker to modify `Object.prototype`. This can be exploited by passing a specially crafted JSON object to the affected APIs, potentially leading to denial of service or remote code execution depending on the application environment. As of the advisory date, the maintainer has not yet released a patch.
Affected products
- RobinHerbots Inputmask Up to 5.0.9
Timeline
- 2026-06-12: disclosed: Issue reported via GitHub issue #2885
- 2026-07-18: advisory: CVE-2026-16150 published