Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.9
CVE-2026-33228: Flatted: Unvalidated JSON Keys Can Pollute Global Prototype
CVE-2026-33228 · published 1 day ago
Summary
Prior to version 3.4.2, Flatted's parse function did not properly check the validity of JSON keys, potentially allowing an attacker to manipulate the global prototype. This could lead to unexpected behavior and security issues in your application. Update to version 3.4.2 or later to fix this issue.
What to do
- Update webreflection flatted to version 3.4.2.
- Update flatted to version 3.4.2.
- Update flatted to version 3.2.2-aikido.2.
- Update rootio @rootio/flatted to version 3.2.2-root.io.2.
- Update rootio @rootio/flatted to version 3.3.3-root.io.2.
- Update rootio @rootio/flatted to version 3.3.2-root.io.3.
- Update rootio @rootio/flatted to version 3.4.1-root.io.1.
- Update rootio @rootio/flatted to version 3.3.2-root.io.4.
- Update flatted to version 3.3.2-aikido.4.
- Update flatted to version 3.2.5-aikido.1.
- Update rootio @rootio/flatted to version 3.2.5-root.io.1.
- Update flatted to version 3.2.9-aikido.2.
- Update rootio @rootio/flatted to version 3.2.9-root.io.2.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| npm | webreflection | flatted |
<= 3.4.1 < 3.4.2 Fix: upgrade to 3.4.2
|
| npm | – | flatted |
<= 3.4.1 < 3.4.2 Fix: upgrade to 3.4.2
|
| Debian:11 | debian | node-flatted | All versions |
| Debian:12 | debian | node-flatted | All versions |
| Debian:13 | debian | node-flatted | All versions |
| Debian:14 | debian | node-flatted | All versions |
| Root:npm | – | flatted |
< 3.2.2-aikido.2 < 3.3.2-aikido.4 < 3.2.5-aikido.1 < 3.2.9-aikido.2 Fix: upgrade to 3.2.2-aikido.2
|
| Root:npm | rootio | @rootio/flatted |
< 3.2.2-root.io.2 < 3.3.3-root.io.2 < 3.3.2-root.io.3 < 3.4.1-root.io.1 < 3.3.2-root.io.4 < 3.2.5-root.io.1 < 3.2.9-root.io.2 Fix: upgrade to 3.2.2-root.io.2
|
| – | webreflection | flatted | < 3.4.2 |
Original advisory text
CVE-2026-33228 in flatted - Patched by Root
Root has patched CVE-2026-33228 in the flatted package for Root:npm. Multiple fixed versions available.
References
- https://security-tracker.debian.org/tracker/CVE-2026-33228 Vendor Advisory
- https://github.com/WebReflection/flatted/security/advisories/GHSA-rf6f-7fwh-wjgh
- https://github.com/advisories/GHSA-rf6f-7fwh-wjgh
- https://github.com/WebReflection/flatted Product
- https://github.com/WebReflection/flatted/commit/885ddcc33cf9657caf38c57c7be45ae1...
- https://github.com/WebReflection/flatted/releases/tag/v3.4.2
- https://access.redhat.com/errata/RHSA-2026:13826
- https://access.redhat.com/errata/RHSA-2026:9742
- https://access.redhat.com/security/cve/CVE-2026-33228
- https://bugzilla.redhat.com/show_bug.cgi?id=2449872
- https://nvd.nist.gov/vuln/detail/CVE-2026-33228
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33228.json
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33228... Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:34342
Severity
8.9
High
CVSS 4.0: 8.9 (GHSA)
CVSS 4.0: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-1321Prototype Pollution
CWE-915Improperly Controlled Modification of Dynamically-Determined Object Attributes
Timeline
Published2 Sep 2026
Updated2 Sep 2026
First seen19 Mar 2026
Sources
DEBIAN-CVE-2026-33228 · OSV
GHSA-rf6f-7fwh-wjgh · GHSA
CVE-2026-33228 · NVD
GHSA-rf6f-7fwh-wjgh · OSV
CVE-2026-33228 · MITRE
CVE-2026-33228 · OSV
Monitor software like this
Free during beta