CVE-2026-5758: Mafintosh's protocol-buffers-schema is vulnerable to prototype pollution
(updated )
JavaScript is vulnerable to prototype pollution in Mafintosh’s protocol-buffers-schema Version 3.6.0, where an attacker may alter the application logic, bypass security checks, cause a DoS or achieve remote code execution.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-5758 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →