JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, the JSON object's "__proto__" member is an own enumerable property, so the for…in enumerates it and the target[key] = source[key] write triggers the Object.prototype.__proto__ setter on the fresh target ({}). The result is a per-instance prototype hijack: Object.prototype itself is untouched, but the merged attributes object now inherits attacker-controlled keys. Because the consuming set() function then enumerates the merged object with another for...in, every key the attacker placed on the polluted prototype lands in the resulting Set-Cookie string as an attribute pair. The attacker can set domain=, secure=, samesite=, expires=, and path= on cookies whose attributes the developer thought were locked down. This issue has been patched in version 3.0.7.
Metrics
Affected Vendors & Products
References
History
Fri, 28 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 26 Aug 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Js-cookie javascript Cookie
Redhat 3scale Api Management Redhat ansible Automation Platform Redhat enterprise Linux Redhat openshift Ai Redhat openshift Lightspeed |
|
| CPEs | cpe:2.3:a:js-cookie:javascript_cookie:*:*:*:*:*:node.js:*:* cpe:2.3:a:redhat:3scale_api_management:2.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:ansible_automation_platform:2.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_ai:-:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_lightspeed:-:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Js-cookie javascript Cookie
Redhat 3scale Api Management Redhat ansible Automation Platform Redhat enterprise Linux Redhat openshift Ai Redhat openshift Lightspeed |
Tue, 25 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 19 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 30 Jun 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat service Mesh |
|
| Weaknesses | CWE-915 | |
| CPEs | cpe:/a:redhat:service_mesh:3.3::el9 | |
| Vendors & Products |
Redhat
Redhat service Mesh |
|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 11 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Js-cookie
Js-cookie js-cookie |
|
| Vendors & Products |
Js-cookie
Js-cookie js-cookie |
Wed, 10 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, the JSON object's "__proto__" member is an own enumerable property, so the for…in enumerates it and the target[key] = source[key] write triggers the Object.prototype.__proto__ setter on the fresh target ({}). The result is a per-instance prototype hijack: Object.prototype itself is untouched, but the merged attributes object now inherits attacker-controlled keys. Because the consuming set() function then enumerates the merged object with another for...in, every key the attacker placed on the polluted prototype lands in the resulting Set-Cookie string as an attribute pair. The attacker can set domain=, secure=, samesite=, expires=, and path= on cookies whose attributes the developer thought were locked down. This issue has been patched in version 3.0.7. | |
| Title | JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection | |
| Weaknesses | CWE-1321 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-06-10T21:18:05.372Z
Updated: 2026-09-09T12:05:08.819Z
Reserved: 2026-05-15T19:34:14.013Z
Link: CVE-2026-46625
Updated: 2026-09-07T12:05:11.501Z
Status : Modified
Published: 2026-06-10T22:16:59.613
Modified: 2026-09-09T13:20:18.357
Link: CVE-2026-46625