Junglewise Threat Intelligence

CVE-2026-54335: Feathersjs prototype pollution in @feathersjs/commons _.merge

CVE-2026-54335 · Severity: low · CVSS 3.7 · Published 2026-07-17

Vendors: npm.

Executive brief

The @feathersjs/commons library contains a merge utility function used by downstream applications to combine data objects. When this function processes JSON-parsed data containing special keys like `__proto__`, it can inadvertently modify the JavaScript prototype chain, affecting all objects created during the application's runtime. While the real-world risk is limited due to the library being used safely by first-party Feathers packages, applications that directly pass untrusted JSON data through this merge function could be affected.

Technical details

This is a prototype pollution vulnerability (CWE-1321) in the _.merge utility exported by @feathersjs/commons. The vulnerable component iterates over Object.keys(source) to recursively merge a source object into a target. When source is produced by JSON.parse() with a `__proto__`, `constructor`, or `prototype` key, Object.keys() returns these as own-enumerable properties. The merge operation then resolves target['__proto__'] to Object.prototype and writes attacker-supplied properties to it, polluting the prototype for all plain objects during the Node process lifetime. The attack requires that a downstream application or plugin pass JSON-parsed, untrusted input directly through commons._.merge; first-party Feathers packages do not do this. The vulnerability affects @feathersjs/commons versions 4.0.0–4.5.19 and 5.0.0–5.0.44. It is patched in versions 4.5.20+ and 5.0.45+, which skip `__proto__`, `constructor`, and `prototype` keys during iteration.

Affected products

  • feathersjs @feathersjs/commons >=4.0.0, <=4.5.19; >=5.0.0, <=5.0.44

Timeline

  • 2026-06-04: disclosed: Advisory published on GitHub
  • 2026-06-04: patched: Fixed in @feathersjs/commons 4.5.20 and 5.0.45
  • 2026-07-14: advisory: OSV and CVE records published

References