CVE-2026-107301: msgpack5: Partial options disable prototype protection
Impact
Passing an empty or partial options object disables the default protoAction: 'error' protection. A map containing a proto key can then replace the prototype of the decoded object, potentially changing inherited properties or causing unexpected behavior in downstream code.
Only the decoded object's prototype is affected; this does not modify Object.prototype globally.
Patches
Options are now merged with secure defaults without modifying the caller's object. Unsupported protoAction values are rejected.
Workarounds
Explicitly set protoAction: 'error' whenever constructing a msgpack5 instance, and validate decoded values before use.
Other sources
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, constructing msgpack5 with an empty or partial options object disables the default protoAction: 'error' protection. A decoded map containing a proto key can then replace the decoded object's prototype, potentially changing inherited properties or downstream behavior, although Object.prototype is not modified globally. This issue is fixed in version 6.1.0.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/msgpack5to a version that resolves this vulnerability.Fixed in 6.1.0 - Upgrade
Upgrade
msgpack5to a version that resolves this vulnerability.Fixed in 6.1.0 - Configuration
Explicitly set protoAction: 'error' whenever constructing a msgpack5 instance.
msgpack5 protoAction = error - Compensating control
Validate decoded values before using them.
Event History
Frequently Asked Questions
Which applications are exposed to this issue?
Applications using msgpack5 before 6.1.0 are exposed if they construct the library with an empty or partial options object and decode attacker-controlled MessagePack maps. The affected behavior applies to msgpack5 for Node.js and browsers.
What must an attacker provide to exploit the weakness?
An attacker needs a decoded MessagePack map containing a __proto__ key. When prototype protection has been disabled by empty or partial constructor options, that key can replace the prototype of the decoded object.
Is the global Object.prototype polluted?
No. The issue can alter the prototype of the individual decoded object, potentially affecting inherited properties or downstream behavior, but it does not modify Object.prototype globally.
What should be done if applications use custom msgpack5 options?
Upgrade msgpack5 to version 6.1.0. Review code that constructs msgpack5 with empty or partial options objects, especially where decoded data can originate from untrusted sources.