JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, the JSON object's "__proto__" member is an own enumerable property, so the for…in enumerates it and the target[key] = source[key] write triggers the Object.prototype.__proto__ setter on the fresh target ({}). The result is a per-instance prototype hijack: Object.prototype itself is untouched, but the merged attributes object now inherits attacker-controlled keys. Because the consuming set() function then enumerates the merged object with another for...in, every key the attacker placed on the polluted prototype lands in the resulting Set-Cookie string as an attribute pair. The attacker can set domain=, secure=, samesite=, expires=, and path= on cookies whose attributes the developer thought were locked down. This issue has been patched in version 3.0.7.
History

Fri, 28 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
References

Wed, 26 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Js-cookie javascript Cookie
Redhat 3scale Api Management
Redhat ansible Automation Platform
Redhat enterprise Linux
Redhat openshift Ai
Redhat openshift Lightspeed
CPEs cpe:2.3:a:js-cookie:javascript_cookie:*:*:*:*:*:node.js:*:*
cpe:2.3:a:redhat:3scale_api_management:2.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_automation_platform:2.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_ai:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_lightspeed:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
Vendors & Products Js-cookie javascript Cookie
Redhat 3scale Api Management
Redhat ansible Automation Platform
Redhat enterprise Linux
Redhat openshift Ai
Redhat openshift Lightspeed

Tue, 25 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
References

Wed, 19 Aug 2026 12:30:00 +0000


Tue, 30 Jun 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat service Mesh
Weaknesses CWE-915
CPEs cpe:/a:redhat:service_mesh:3.3::el9
Vendors & Products Redhat
Redhat service Mesh
References
Metrics threat_severity

None

threat_severity

Important


Thu, 11 Jun 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 11 Jun 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Js-cookie
Js-cookie js-cookie
Vendors & Products Js-cookie
Js-cookie js-cookie

Wed, 10 Jun 2026 21:45:00 +0000

Type Values Removed Values Added
Description JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, the JSON object's "__proto__" member is an own enumerable property, so the for…in enumerates it and the target[key] = source[key] write triggers the Object.prototype.__proto__ setter on the fresh target ({}). The result is a per-instance prototype hijack: Object.prototype itself is untouched, but the merged attributes object now inherits attacker-controlled keys. Because the consuming set() function then enumerates the merged object with another for...in, every key the attacker placed on the polluted prototype lands in the resulting Set-Cookie string as an attribute pair. The attacker can set domain=, secure=, samesite=, expires=, and path= on cookies whose attributes the developer thought were locked down. This issue has been patched in version 3.0.7.
Title JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection
Weaknesses CWE-1321
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-06-10T21:18:05.372Z

Updated: 2026-09-09T12:05:08.819Z

Reserved: 2026-05-15T19:34:14.013Z

Link: CVE-2026-46625

cve-icon Vulnrichment

Updated: 2026-09-07T12:05:11.501Z

cve-icon NVD

Status : Modified

Published: 2026-06-10T22:16:59.613

Modified: 2026-09-09T13:20:18.357

Link: CVE-2026-46625

cve-icon Redhat

Severity : Important

Publid Date: 2026-06-10T21:18:05Z

Links: CVE-2026-46625 - Bugzilla