Junglewise Threat Intelligence

CVE-2026-59952: Valibot TypeError in flatten helper via prototype key collision

CVE-2026-59952 · Severity: medium · CVSS 4 · Published 2026-07-30

Vendors: npm.

Executive brief

Valibot is a popular data validation library for JavaScript applications. A flaw in its flatten() error-handling helper can cause it to throw an unexpected TypeError when validation errors involve inherited JavaScript object property names like "toString" or "valueOf". Applications that use Valibot to validate user-supplied JSON objects and then flatten validation errors for API responses could crash instead of returning normal error messages, causing service unavailability.

Technical details

The vulnerability is a logic error in the flatten() and merge utilities when processing object keys that collide with inherited Object.prototype properties. The record() schema intentionally filters __proto__, prototype, and constructor, but accepts other inherited property names (toString, valueOf, hasOwnProperty, etc.) as valid own keys. When validation rejects such entries, Valibot creates issue paths containing these keys. The flatten() function stores nested errors in a plain object and uses truthiness checks: if the dot path resolves to an inherited function (e.g., Object.prototype.toString), the subsequent .push() call fails with TypeError. The attack vector requires (1) attacker-controlled JSON input to a record() schema, (2) validation failure on a key matching an inherited property name, and (3) calling flatten() on the resulting issues—a common pattern in API validation. The fix uses Object.prototype.hasOwnProperty.call() instead of truthiness checks and initializes error containers with Object.create(null). Patch available in version 1.4.2.

Affected products

  • open-circle valibot <= 1.4.1

Timeline

  • 2026-07-24: disclosed: GHSA-5qjj-4xww-7phc published; CVE-2026-59952 assigned
  • 2026-06-28: patched: Fix merged via PR #1522
  • 2026-07-08: advisory: Security advisory published on GitHub

References

Related threats