CVE Explorer
CVE-2026-45302
parse-nested-form-data is a tiny node module for parsing FormData by name into objects and arrays. Prior to version 1.0.1, parseFormData() walks bracket and dot-notation FormData field names into nested objects without filtering reserved property keys. A single FormData field whose name begins with __proto__, or contains .__proto__. mid-path, causes the parser to traverse onto Object.prototype and assign properties there, polluting the prototype chain of every plain object in the running process
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"parse-nested-form-data","vendor":"milamer","versions":[{"status":"affected","version":"< 1.0.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:98f0486c8878e5bea0dd75091905d197c691f3b134fa273b114a55abc83f7b8c · sha256:fd244a6182a5385c… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":8.2,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:98f0486c8878e5bea0dd75091905d197c691f3b134fa273b114a55abc83f7b8c · sha256:fd244a6182a5385c… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-1321","description":"CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:98f0486c8878e5bea0dd75091905d197c691f3b134fa273b114a55abc83f7b8c · sha256:fd244a6182a5385c… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"https://github.com/milamer/parse-nested-form-data/commit/527ad58eb486e32438f7198fb88315c20449d792","tags":["x_refsource_MISC"],"url":"https://github.com/milamer/parse-nested-form-data/commit/527ad58eb486e32438f7198fb88315c20449d792"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:98f0486c8878e5bea0dd75091905d197c691f3b134fa273b114a55abc83f7b8c · sha256:fd244a6182a5385c… · /containers/cna/references/1
{"name":"https://github.com/milamer/parse-nested-form-data/releases/tag/v1.0.1","tags":["x_refsource_MISC"],"url":"https://github.com/milamer/parse-nested-form-data/releases/tag/v1.0.1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:98f0486c8878e5bea0dd75091905d197c691f3b134fa273b114a55abc83f7b8c · sha256:fd244a6182a5385c… · /containers/cna/references/2
{"tags":["exploit"],"url":"https://github.com/milamer/parse-nested-form-data/security/advisories/GHSA-xp7r-j8r6-j9h3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:98f0486c8878e5bea0dd75091905d197c691f3b134fa273b114a55abc83f7b8c · sha256:fd244a6182a5385c… · /containers/adp/0/references/0
{"name":"https://github.com/milamer/parse-nested-form-data/security/advisories/GHSA-xp7r-j8r6-j9h3","tags":["x_refsource_CONFIRM"],"url":"https://github.com/milamer/parse-nested-form-data/security/advisories/GHSA-xp7r-j8r6-j9h3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:98f0486c8878e5bea0dd75091905d197c691f3b134fa273b114a55abc83f7b8c · sha256:fd244a6182a5385c… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.