A prototype pollution vulnerability has been identified in ractivejs/ractive up to version 1.4.4. The flaw resides in the Ractive#set function within the Keypath Handler component, allowing improperly controlled modification of object prototype attributes. The vulnerability can be exploited remotely, and a public exploit is already available, increasing the risk of active attacks. The project maintainers were notified via an issue report but have not yet responded or released a patch. This type of vulnerability can lead to serious consequences including denial of service, property injection, or remote code execution depending on the application context.