A prototype pollution vulnerability has been identified in ractivejs/ractive up to version 1.4.4. The flaw exists in the Ractive#set function within the Keypath Handler component, allowing improperly controlled modification of object prototype attributes. The vulnerability can be exploited remotely, and a public exploit is already available, increasing the risk of active attacks. The project maintainers were notified via an issue report but have not yet responded or released a patch. The unpatched status combined with public exploit availability makes this a high-severity concern. Prototype pollution vulnerabilities can lead to application logic bypass, denial of service, or remote code execution depending on the context. Users of ractivejs ractive up to version 1.4.4 are advised to monitor for patches and apply mitigations as available.