CVE Explorer
CVE-2026-28794
oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1.13.6, a prototype pollution vulnerability exists in the RPC JSON deserializer of the @orpc/client package. The vulnerability allows unauthenticated, remote attackers to inject arbitrary properties into the global Object.prototype. Because this pollution persists for the lifetime of the Node.js process and affects all objects, it can lead to severe security breaches, including a
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"orpc","vendor":"middleapi","versions":[{"status":"affected","version":"< 1.13.6"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:c4fe71ce386fec5375d9ce6620aa11ba5abdc40c99dc39562c209236aff6f38b · sha256:42170659ea1f01c2… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":9.3,"baseSeverity":"CRITICAL","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:c4fe71ce386fec5375d9ce6620aa11ba5abdc40c99dc39562c209236aff6f38b · sha256:42170659ea1f01c2… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-1321","description":"CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:c4fe71ce386fec5375d9ce6620aa11ba5abdc40c99dc39562c209236aff6f38b · sha256:42170659ea1f01c2… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/middleapi/orpc/commit/1dba06fc6f938c2486de303c2fa096bc1c8418b5","tags":["x_refsource_MISC"],"url":"https://github.com/middleapi/orpc/commit/1dba06fc6f938c2486de303c2fa096bc1c8418b5"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c4fe71ce386fec5375d9ce6620aa11ba5abdc40c99dc39562c209236aff6f38b · sha256:42170659ea1f01c2… · /containers/cna/references/1
{"name":"https://github.com/middleapi/orpc/security/advisories/GHSA-m272-9rp6-32mc","tags":["x_refsource_CONFIRM"],"url":"https://github.com/middleapi/orpc/security/advisories/GHSA-m272-9rp6-32mc"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c4fe71ce386fec5375d9ce6620aa11ba5abdc40c99dc39562c209236aff6f38b · sha256:42170659ea1f01c2… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.