Junglewise Threat Intelligence

CVE-2026-54639: Style Dictionary prototype pollution in convertTokenData utility

CVE-2026-54639 · Severity: high · CVSS 8.8 · Published 2026-06-24

Vendors: Amazon.

Executive brief

Style Dictionary, a tool for managing design tokens across platforms, is vulnerable to a security flaw that allows malicious data to interfere with the underlying application's memory. If an attacker can provide a specially crafted design token, they can modify global object properties, potentially leading to application crashes or unauthorized behavior. This is particularly serious for applications that process user-provided design tokens on a server.

Technical details

A prototype pollution vulnerability exists in the `convertTokenData()` utility function of Style Dictionary. The flaw occurs when processing token arrays where a key contains the `__proto__` property, such as `[{ key: '{__proto__.foo}', value: 'malicious' }]`. This allows an attacker to pollute the global `Object.prototype`. The vulnerability can be triggered through direct calls to `convertTokenData`, the Expand API, or during the standard transform lifecycle. A patch is available in version 5.4.4.

Affected products

  • Amazon style-dictionary >= 4.3.0, < 5.4.4

Timeline

  • 2026-06-08: disclosed: Initial disclosure to maintainers
  • 2026-06-24: advisory: NVD publication date
  • 2026-07-28: patched: GitHub Advisory published and patch confirmed in v5.4.4

References