Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-1774: casl/ability package could let attackers bypass permissions
CVE-2026-1774 · published 2 days ago
Summary
The @casl/ability library used in your applications can be tricked into granting actions it shouldn’t. This could let a malicious user perform operations they are not supposed to. Update to the latest patched version provided by Root to close the gap.
What to do
- Update casl ability to version 6.7.5.
- Update casl @casl/ability to version 6.7.2-aikido.1.
- Update rootio @rootio/casl__ability to version 6.7.2-root.io.1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| npm | casl | ability |
>= 2.4.0, <= 6.7.4 Fix: upgrade to 6.7.5
|
| Root:npm | casl | @casl/ability |
< 6.7.2-aikido.1 Fix: upgrade to 6.7.2-aikido.1
|
| Root:npm | rootio | @rootio/casl__ability |
< 6.7.2-root.io.1 Fix: upgrade to 6.7.2-root.io.1
|
Original advisory text
CVE-2026-1774 in @casl/ability - Patched by Root
Root has patched CVE-2026-1774 in the @casl/ability package for Root:npm. Multiple fixed versions available.
References
- https://cwe.mitre.org/data/definitions/1321.html
- https://developer.mozilla.org/en-US/docs/Web/Security/Attacks/Prototype_pollutio...
- https://github.com/stalniy/casl/tree/master/packages/casl-ability
- https://www.kb.cert.org/vuls/id/458422
- https://nvd.nist.gov/vuln/detail/CVE-2026-1774
- https://github.com/stalniy/casl/pull/1093
- https://github.com/stalniy/casl/commit/39da920ec1dfadf3655e28bd0389e960ac6871f4
- https://github.com/advisories/GHSA-x9vf-53q3-cvx6
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-1321Prototype Pollution
Timeline
Published8 Oct 2026
Updated8 Oct 2026
First seen6 Mar 2026
Track software like this
Free during beta