CVE-2026-91860 | Vaadin Vaadin/Vaadin Charts/Vaadin Component Base @vaadin prototype pollution
A vulnerability classified as critical was found in Vaadin Vaadin, Vaadin Charts and Vaadin Component Base. This vulnerability affects unknown code of the component @vaadin/charts/@vaadin/component-base/Deep Merge Helpers. Such manipulation leads to improperly controlled modification of object prototype attributes.
This vulnerability is listed as CVE-2026-91860. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More