CVE-2026-54639 | style-dictionary up to 5.4.3 Expand API prototype pollution (GHSA-vj5c-m527-mpff)

SecurityVulns

A vulnerability categorized as problematic has been discovered in style-dictionary up to 5.4.3. Affected is an unknown function of the component Expand API. Executing a manipulation can lead to improperly controlled modification of object prototype attributes.

This vulnerability appears as CVE-2026-54639. The attack requires local access. There is no available exploit.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More