CVE-2026-61534 | yayson up to 4.2.0 Deserialization Logic Store.sync Type prototype pollution
A vulnerability classified as critical was found in yayson up to 4.2.0. Affected by this vulnerability is the function Store.sync of the component Deserialization Logic. Executing a manipulation of the argument Type can lead to improperly controlled modification of object prototype attributes.
This vulnerability appears as CVE-2026-61534. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.VulDB Recent EntriesRead More