CVE-2026-107353: Ljharb Traverse

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

traverse (npm) versions 0.3.6 through 0.3.9, 0.4.0 through 0.4.6, 0.5.0 through 0.5.2, and 0.6.0 through 0.6.11 allow prototype pollution through set(). When the path passed to set() crosses a primitive value, the next path segment is resolved on that primitive's built-in prototype, so an application that passes an untrusted path to set() lets an attacker add or overwrite properties of String.prototype, Number.prototype, or Boolean.prototype using plain JSON data, for example traverse({ name: 'bob' }).set(['name', '__proto__', 'polluted'], 'yes'). Object.prototype was reachable only with a non-data path segment, such as an object whose toString returns a different value on each call, or through a Proxy that accepts an assignment without storing it. This is fixed in 0.3.10, 0.4.7, 0.5.3, and 0.6.12.

Affected products

  • Ljharb Traverse: from 0.3.6, before 0.3.10 (fixed in 0.3.10); from 0.4.0, before 0.4.7 (fixed in 0.4.7); from 0.5.0, before 0.5.3 (fixed in 0.5.3); from 0.6.0, before 0.6.12 (fixed in 0.6.12)

Published 2026-10-07. Last modified 2026-10-08.