PatchSiren cyber security CVE debrief
CVE-2026-106448 StableLib CVE debrief
CVE-2026-106448 is a high-severity vulnerability in StableLib, a TypeScript and JavaScript library. The vulnerability allows for prototype poisoning via __proto__ map keys in CBOR decoding, potentially leading to security-sensitive decisions being made using inherited attacker data. This issue affects applications using StableLib versions prior to 2.0.4. Defenders should assess exposure and prioritize verification and remediation efforts. The vulnerability is caused by the @stablelib/cbor CBOR map decoding path creating ordinary JavaScript objects and assigning attacker-controlled keys with bracket assignment.
- Vendor
- StableLib
- Product
- Unknown
- CVSS
- HIGH 8.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-04
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-04-04
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for TypeScript and JavaScript applications using StableLib should assess exposure and prioritize verification and remediation efforts. This includes reviewing the version of StableLib in use, upgrading to version 2.0.4 or later, and reviewing downstream code that trusts normal property lookup or merges the decoded object. Security teams and vulnerability management teams should also be aware of this vulnerability and its potential to
Why it matters
CVE-2026-106448 is a high-severity vulnerability in StableLib that allows for prototype poisoning via __proto__ map keys in CBOR decoding, potentially leading to security-sensitive decisions being made using inherited attacker data. Defenders should prioritize verifying the version of StableLib in use and upgrading to version 2.0.4 or later to mitigate this vulnerability.
- Security-sensitive decisions may be made using inherited attacker data
- Downstream code that trusts normal property lookup or merges the decoded object may be affected
- Verification of the version of StableLib in use is necessary
- Remediation requires upgrading to version 2.0.4 or later
Technical summary
The @stablelib/cbor CBOR map decoding path creates ordinary JavaScript objects and assigns attacker-controlled keys with bracket assignment. A map key named __proto__ invokes the inherited prototype setter instead of creating an ordinary own property, allowing the decoded object's prototype to contain attacker-controlled authorization or feature-flag values. This can lead to security-sensitive decisions being made using inherited attacker data. The vulnerability is fixed in version 2.0.4 of StableLib, which changes the decoding path to properly handle __proto__ map keys.
Defensive priority
Defenders should prioritize verifying the version of StableLib in use and upgrading to version 2.0.4 or later to mitigate this vulnerability.
Recommended defensive actions
- Verify the version of StableLib in use
- Upgrade to version 2.0.4 or later
- Review downstream code that trusts normal property lookup or merges the decoded object
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description, affected versions, and fixed version. The vulnerability is fixed in version 2.0.4 of StableLib. Defenders should verify the version of StableLib in use and review downstream code that trusts normal property lookup or merges the decoded object. The CVE record was published on 2026-10-06T19:45:02.616Z and has not been modified since then. There are no known ransomware campaigns using this vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-106448 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-106448
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-106448 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106448
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
StableLib: Prototype poisoning via `__proto__` map keys in CBOR decoding
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/106xxx/CVE-2026-106448.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/StableLib/stablelib/security/advisories/GHSA-w48f-fwg7-ww6p
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/StableLib/stablelib/commit/0f153a63b7552a0e8721f640984113e419015026
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/StableLib/stablelib/releases/tag/@stablelib/[email protected]
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.