CVE-2026-103918: @orpc/zod: Prototype injection in smart coercion
oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.10, the @orpc/zod ZodSmartCoercionPlugin and experimentalZodSmartCoercionPlugin collect object and record properties in plain objects and resolve shape keys through the prototype chain. A remote client that can reach a procedure with an object or record input can supply proto to replace the prototype of the returned request object, allowing attacker-controlled inherited values to reach application lookups. For object schemas, keys such as constructor, toString, and proto can instead resolve inherited members as Zod schemas and cause an unhandled TypeError before validation. The global Object.prototype, unrelated objects, other requests, and other users are not modified, and the availability effect is limited to crafted requests rather than persistent process-wide state. This issue is fixed in version 1.14.10.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@orpc/zodto a version that resolves this vulnerability.Fixed in 1.14.10
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments using @orpc/zod before 1.14.10 are exposed if they use ZodSmartCoercionPlugin or experimental_ZodSmartCoercionPlugin on a procedure that accepts object or record input. A remote client only needs network access to such a procedure; no authentication or user interaction is required by the stated vector.
What can an attacker do through a crafted request?
An attacker can submit __proto__ to replace the prototype of the returned request object, causing attacker-controlled inherited values to be used by application lookups. For object schemas, crafted keys including constructor, toString, or __proto__ can also trigger an unhandled TypeError before validation.
Does this create persistent prototype pollution across the application?
No. The global Object.prototype, unrelated objects, other requests, and other users are not modified. Availability impact is limited to crafted requests rather than persistent process-wide state.
What version contains the fix?
The issue is fixed in @orpc/zod version 1.14.10.