← Back to overview

A prototype pollution vulnerability has been identified in ractivejs/ractive up to version 1.4.4. The flaw resides in the Ractive#set function within the Keypath Handler component, allowing improperly controlled modification of object prototype attributes. The vulnerability can be exploited remotely, and a public exploit is already available, increasing the risk of active attacks. The project maintainers were notified via an issue report but have not yet responded or released a patch. This type of vulnerability can lead to serious consequences including denial of service, property injection, or remote code execution depending on the application context.

Affected products

  • ractivejs/ractive up to 1.4.4

Related CVE's

  • CVE-2026-78181

Categories

  • Supply Chain & Dependencies
  • Web Technologies
  • Zero-Day Vulnerabilities