Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. scim-patch
  4. ›
  5. CVE-2026-61834

CVE-2026-61834: scim-patch: Mutation of Inherited Built-in Method Objects

September 28, 2026

Incomplete Prototype Pollution Fix Allows Mutation of Inherited Built-in Method Objects

scim-patch blocks direct dangerous path segments such as __proto__, constructor, and prototype, but still traverses inherited properties when applying SCIM patch paths.

An attacker who controls a SCIM PATCH operation can use paths such as toString.polluted to mutate shared built-in function objects, for example Object.prototype.toString.

References

  • github.com/advisories/GHSA-2mhw-wcx5-v3xj
  • github.com/thomaspoignant/scim-patch/commit/c86474f7a9b16191d939f59ba94eca6c6e63044b
  • github.com/thomaspoignant/scim-patch/pull/1127
  • github.com/thomaspoignant/scim-patch/releases/tag/v0.9.2
  • github.com/thomaspoignant/scim-patch/security/advisories/GHSA-2mhw-wcx5-v3xj
  • nvd.nist.gov/vuln/detail/CVE-2026-61834

Code Behaviors & Features

Detect and mitigate CVE-2026-61834 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.9.2

Fixed versions

  • 0.9.2

Solution

Upgrade to version 0.9.2 or above.

Impact 4.3 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
  • CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes

Source file

npm/scim-patch/CVE-2026-61834.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 29 Sep 2026 12:17:58 +0000.