Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-1774: casl/ability package could let attackers bypass permissions

CVE-2026-1774 · published 2 days ago
Summary

The @casl/ability library used in your applications can be tricked into granting actions it shouldn’t. This could let a malicious user perform operations they are not supposed to. Update to the latest patched version provided by Root to close the gap.

What to do
  • Update casl ability to version 6.7.5.
  • Update casl @casl/ability to version 6.7.2-aikido.1.
  • Update rootio @rootio/casl__ability to version 6.7.2-root.io.1.
Affected software
Ecosystem VendorProductAffected versions
npm casl ability >= 2.4.0, <= 6.7.4
Fix: upgrade to 6.7.5
Root:npm casl @casl/ability < 6.7.2-aikido.1
Fix: upgrade to 6.7.2-aikido.1
Root:npm rootio @rootio/casl__ability < 6.7.2-root.io.1
Fix: upgrade to 6.7.2-root.io.1
Original advisory text
CVE-2026-1774 in @casl/ability - Patched by Root
Root has patched CVE-2026-1774 in the @casl/ability package for Root:npm. Multiple fixed versions available.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-1321Prototype Pollution
Timeline
Published8 Oct 2026
Updated8 Oct 2026
First seen6 Mar 2026
Track software like this
Free during beta