CVE-2026-107353 | ljharb traverse up to 0.3.9/0.4.6/0.5.2/0.6.11 set path prototype pollution

SecurityVulns

A vulnerability, which was classified as critical, has been found in ljharb traverse up to 0.3.9/0.4.6/0.5.2/0.6.11. This vulnerability affects the function Set. Performing a manipulation of the argument path results in improperly controlled modification of object prototype attributes.

This vulnerability was named CVE-2026-107353. The attack may be initiated remotely. There is no available exploit.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More