CVE-2026-46625

EUVD-2026-36154
JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, the JSON object's "__proto__" member is an own enumerable property, so the for…in enumerates it and the target[key] = source[key] write triggers the Object.prototype.__proto__ setter on the fresh target ({}). The result is a per-instance prototype hijack: Object.prototype itself is untouched, but the merged attributes object now inherits attacker-controlled keys. Because the consuming set() function then enumerates the merged object with another for...in, every key the attacker placed on the polluted prototype lands in the resulting Set-Cookie string as an attribute pair. The attacker can set domain=, secure=, samesite=, expires=, and path= on cookies whose attributes the developer thought were locked down. This issue has been patched in version 3.0.7.
Prototype Pollution
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 58.16%
Affected Products (NVD)
VendorProductVersion
js-cookiejavascript_cookie
𝑥
< 3.0.7
redhat3scale_api_management
2.0
redhatansible_automation_platform
2.0
redhatopenshift_ai
-
redhatopenshift_lightspeed
-
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
redhatenterprise_linux
10.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatCryostat 4 on RHEL 9
4.2.0-13 ≤
𝑥
< *
ADP
Red HatRed Hat Advanced Cluster Security for Kubernetes 4.10
1783357140 ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.1
1787047114 ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.2
1787047188 ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.7
1787218409 ≤
𝑥
< *
ADP
Red HatRed Hat Developer Hub 1.10
1785333413 ≤
𝑥
< *
ADP
Red HatRed Hat Developer Hub 1.10
1785340831 ≤
𝑥
< *
ADP
Red HatRed Hat Developer Hub 1.10
1785332928 ≤
𝑥
< *
ADP
Red HatRed Hat Developer Hub 1.10
1785411652 ≤
𝑥
< *
ADP
Red HatRed Hat Developer Hub 1.9
1785972843 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 3.4
1787347991 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 3.4
1787250508 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 3.4
1787251550 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 3.4
1786611759 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 3.4
1787251250 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 3.4
1786612219 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 3.4
1787250617 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Service Mesh 3.3
1782231869 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Service Mesh 3.3
1782201466 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
node-js-cookie
bookworm
postponed
bullseye
postponed
forky
3.0.8+~3.0.6-1
fixed
sid
3.0.8+~3.0.6-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-js-cookie
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage