CVE-2026-78181: ractivejs ractive Keypath Ractive#set prototype pollution
A weakness has been identified in ractivejs ractive up to 1.4.4. Impacted is the function Ractive#set of the component Keypath Handler. Executing a manipulation can lead to improperly controlled modification of object prototype attributes. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
Deployments using ractivejs/ractive up to version 1.4.4 are identified as affected. The available data does not identify a fixed version or indicate whether any particular application configuration avoids exposure.
Does exploitation require authentication or user interaction?
No. The supplied severity vector indicates network reachability, low attack complexity, no privileges required, and no user interaction required.
Is public exploit code available?
Yes. The data states that an exploit has been made publicly available and could be used in attacks.
What should teams do if no vendor response or patch is available?
The provided information does not identify a patch or workaround. Teams should identify use of ractivejs/ractive versions through 1.4.4 and prioritize exposure review because remote, unauthenticated exploitation is described.