CVE-2026-61834
4.3 MEDIUMpublic exploit availablePublished 2026-09-23 · Updated 2026-09-23
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
scim-patch is a library for applying SCIM patch operations. Prior to 0.9.2, navigate() reads inherited properties and assign() uses prototype-chain membership checks while resolving attacker-controlled SCIM PATCH paths. A path or one of the dotted value keys beginning with an inherited property such as toString can therefore traverse into a shared built-in function object and add attacker-controlled properties, causing process-global mutation that may affect application logic reading inherited-method properties. This issue is fixed in version 0.9.2.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weaknesses
CWE-915, CWE-1321
Public exploit & PoC references
- https://github.com/thomaspoignant/scim-patch/commit/c86474f7a9b16191d939f59ba94eca6c6e63044b
- https://github.com/thomaspoignant/scim-patch/pull/1127
- https://github.com/thomaspoignant/scim-patch/releases/tag/v0.9.2
- https://github.com/thomaspoignant/scim-patch/security/advisories/GHSA-2mhw-wcx5-v3xj
- https://github.com/thomaspoignant/scim-patch/security/advisories/GHSA-2mhw-wcx5-v3xj
All references
- https://github.com/thomaspoignant/scim-patch/commit/c86474f7a9b16191d939f59ba94eca6c6e63044b
- https://github.com/thomaspoignant/scim-patch/pull/1127
- https://github.com/thomaspoignant/scim-patch/releases/tag/v0.9.2
- https://github.com/thomaspoignant/scim-patch/security/advisories/GHSA-2mhw-wcx5-v3xj
- https://github.com/thomaspoignant/scim-patch/security/advisories/GHSA-2mhw-wcx5-v3xj
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- UNSCOREDCVE-2026-101900PoC
- UNSCOREDCVE-2026-101902PoC
- UNSCOREDCVE-2026-101904PoC
- UNSCOREDCVE-2026-101905PoC
- UNSCOREDCVE-2026-101908PoC
- UNSCOREDCVE-2026-101909PoC
- MEDIUMCVE-2026-14574PoC
- UNSCOREDCVE-2026-61598PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.