Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.9

CVE-2026-33228: Flatted: Unvalidated JSON Keys Can Pollute Global Prototype

CVE-2026-33228 · published 1 day ago
Summary

Prior to version 3.4.2, Flatted's parse function did not properly check the validity of JSON keys, potentially allowing an attacker to manipulate the global prototype. This could lead to unexpected behavior and security issues in your application. Update to version 3.4.2 or later to fix this issue.

What to do
  • Update webreflection flatted to version 3.4.2.
  • Update flatted to version 3.4.2.
  • Update flatted to version 3.2.2-aikido.2.
  • Update rootio @rootio/flatted to version 3.2.2-root.io.2.
  • Update rootio @rootio/flatted to version 3.3.3-root.io.2.
  • Update rootio @rootio/flatted to version 3.3.2-root.io.3.
  • Update rootio @rootio/flatted to version 3.4.1-root.io.1.
  • Update rootio @rootio/flatted to version 3.3.2-root.io.4.
  • Update flatted to version 3.3.2-aikido.4.
  • Update flatted to version 3.2.5-aikido.1.
  • Update rootio @rootio/flatted to version 3.2.5-root.io.1.
  • Update flatted to version 3.2.9-aikido.2.
  • Update rootio @rootio/flatted to version 3.2.9-root.io.2.
Affected software
Ecosystem VendorProductAffected versions
npm webreflection flatted <= 3.4.1
< 3.4.2
Fix: upgrade to 3.4.2
npm flatted <= 3.4.1
< 3.4.2
Fix: upgrade to 3.4.2
Debian:11 debian node-flatted All versions
Debian:12 debian node-flatted All versions
Debian:13 debian node-flatted All versions
Debian:14 debian node-flatted All versions
Root:npm flatted < 3.2.2-aikido.2
< 3.3.2-aikido.4
< 3.2.5-aikido.1
< 3.2.9-aikido.2
Fix: upgrade to 3.2.2-aikido.2
Root:npm rootio @rootio/flatted < 3.2.2-root.io.2
< 3.3.3-root.io.2
< 3.3.2-root.io.3
< 3.4.1-root.io.1
< 3.3.2-root.io.4
< 3.2.5-root.io.1
< 3.2.9-root.io.2
Fix: upgrade to 3.2.2-root.io.2
webreflection flatted < 3.4.2
Original advisory text
CVE-2026-33228 in flatted - Patched by Root
Root has patched CVE-2026-33228 in the flatted package for Root:npm. Multiple fixed versions available.
Severity
8.9 High
CVSS 4.0: 8.9 (GHSA)
CVSS 4.0: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-1321Prototype Pollution
CWE-915Improperly Controlled Modification of Dynamically-Determined Object Attributes
Timeline
Published2 Sep 2026
Updated2 Sep 2026
First seen19 Mar 2026
Monitor software like this
Free during beta