Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. style-dictionary
  4. ›
  5. CVE-2026-54639

CVE-2026-54639: Style Dictionary - Prototype Pollution in convertTokenData utility function

July 28, 2026

Prototype pollution. A malicious user can create a token array [{ key: '{__proto__.foo}', value: 'malicious' }], when processed by convertTokenData() utility function, it will pollute the Object.prototype globally where {}.foo will equal { key: '{__proto__.foo}', value: 'malicious' }.

This has been confirmed with a test/reproduction.

You are impacted when:

  • direct usage of convertTokenData(tokens, { output: 'object' });
  • indirect usage, via using Expand API https://styledictionary.com/reference/config/#expand. If your expand config deems it necessary to run expand (this means, if NOT: 1) set to false, 2) all subprops set to false, or 3) undefined), then we sync the sd.tokens property with the sd.tokenMap property by converting tokenData map back to object.
  • indirect usage via SD’s transform lifecycle. Once your tokens are transformed, we also have to sync the sd.tokens property with the sd.tokenMap property.

Impact is high for this when style-dictionary is used as an integration in a NodeJS server application. Impact is moderate for when style-dictionary is used as an integration in a Web application. Impact is low for most common cases where the user of style-dictionary also maintains the tokens, and access is limited via read/write access to the repository/workflows where it is used.

References

  • github.com/advisories/GHSA-vj5c-m527-mpff
  • github.com/style-dictionary/style-dictionary/commit/209085d9782cfc0783c4d983f3f1bb2c515954ec
  • github.com/style-dictionary/style-dictionary/commit/23b5e8dda143441f0d6b8e2b4222e2da98058bc5
  • github.com/style-dictionary/style-dictionary/pull/1702
  • github.com/style-dictionary/style-dictionary/releases/tag/v5.4.4
  • github.com/style-dictionary/style-dictionary/security/advisories/GHSA-vj5c-m527-mpff
  • nvd.nist.gov/vuln/detail/CVE-2026-54639

Code Behaviors & Features

Detect and mitigate CVE-2026-54639 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 4.3.0 before 5.4.4

Fixed versions

  • 5.4.4

Solution

Upgrade to version 5.4.4 or above.

Impact 8.8 HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Source file

npm/style-dictionary/CVE-2026-54639.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 29 Jul 2026 12:18:54 +0000.