VU#907705: Graphql-upload-minimal has a prototype pollution vulnerability.

2026-03-12T20:52:08Zb2136c1b0593859f3d0cb38cd6f060dff4319ba25e84bb8ae56fbc0d023e2802
arbitrary-file-writeav-evasioncommand-injectiondenial-of-serviceendpoint-detection-and-responsejavascriptnodejspath-traversalpdfpickleprototype-pollutionpythonrceremote-code-executionsupply-chaintls-fingerprintingunsafe-deserializationzip

What happened

A collection of CERT vulnerability notes covering multiple high-impact issues: prototype-pollution in Node.js libraries (graphql-upload-minimal and CASL Ability) allowing global Object.prototype modification; unsafe Python pickle deserialization in the SGLang serving framework enabling unauthenticated remote code execution (CVE-2026-3059, CVE-2026-3060) and an additional pickle-based RCE (CVE-2026-3989); malformed ZIP archive techniques that can evade antivirus/EDR scanning; a TLS handshake fingerprinting flaw in Rakuten Viber Cloak proxy modes that reveals proxy usage; a command injection / R

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
b2136c1b0593859f3d0cb38cd6f060dff4319ba25e84bb8ae56fbc0d023e2802
Enrichment time
2026-03-12T20:52:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.