PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106448 StableLib CVE debrief

CVE-2026-106448 is a high-severity vulnerability in StableLib, a TypeScript and JavaScript library. The vulnerability allows for prototype poisoning via __proto__ map keys in CBOR decoding, potentially leading to security-sensitive decisions being made using inherited attacker data. This issue affects applications using StableLib versions prior to 2.0.4. Defenders should assess exposure and prioritize verification and remediation efforts. The vulnerability is caused by the @stablelib/cbor CBOR map decoding path creating ordinary JavaScript objects and assigning attacker-controlled keys with bracket assignment.

Vendor
StableLib
Product
Unknown
CVSS
HIGH 8.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-04
Original CVE updated
2026-10-07
Advisory published
2026-04-04
Advisory updated
2026-10-07

Who should care

Defenders responsible for TypeScript and JavaScript applications using StableLib should assess exposure and prioritize verification and remediation efforts. This includes reviewing the version of StableLib in use, upgrading to version 2.0.4 or later, and reviewing downstream code that trusts normal property lookup or merges the decoded object. Security teams and vulnerability management teams should also be aware of this vulnerability and its potential to

Why it matters

CVE-2026-106448 is a high-severity vulnerability in StableLib that allows for prototype poisoning via __proto__ map keys in CBOR decoding, potentially leading to security-sensitive decisions being made using inherited attacker data. Defenders should prioritize verifying the version of StableLib in use and upgrading to version 2.0.4 or later to mitigate this vulnerability.

  • Security-sensitive decisions may be made using inherited attacker data
  • Downstream code that trusts normal property lookup or merges the decoded object may be affected
  • Verification of the version of StableLib in use is necessary
  • Remediation requires upgrading to version 2.0.4 or later

Technical summary

The @stablelib/cbor CBOR map decoding path creates ordinary JavaScript objects and assigns attacker-controlled keys with bracket assignment. A map key named __proto__ invokes the inherited prototype setter instead of creating an ordinary own property, allowing the decoded object's prototype to contain attacker-controlled authorization or feature-flag values. This can lead to security-sensitive decisions being made using inherited attacker data. The vulnerability is fixed in version 2.0.4 of StableLib, which changes the decoding path to properly handle __proto__ map keys.

Defensive priority

Defenders should prioritize verifying the version of StableLib in use and upgrading to version 2.0.4 or later to mitigate this vulnerability.

Recommended defensive actions

  • Verify the version of StableLib in use
  • Upgrade to version 2.0.4 or later
  • Review downstream code that trusts normal property lookup or merges the decoded object
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The CVE record and source item provide details on the vulnerability, including its description, affected versions, and fixed version. The vulnerability is fixed in version 2.0.4 of StableLib. Defenders should verify the version of StableLib in use and review downstream code that trusts normal property lookup or merges the decoded object. The CVE record was published on 2026-10-06T19:45:02.616Z and has not been modified since then. There are no known ransomware campaigns using this vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106448 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106448

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106448 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106448

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • StableLib: Prototype poisoning via `__proto__` map keys in CBOR decoding

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/106xxx/CVE-2026-106448.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/StableLib/stablelib/security/advisories/GHSA-w48f-fwg7-ww6p

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/StableLib/stablelib/commit/0f153a63b7552a0e8721f640984113e419015026

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/StableLib/stablelib/releases/tag/@stablelib/[email protected]

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.