LOW
node-opcua
CVE published 2026-09-16
CVE-2026-69200
CVE-2026-69200 is a vulnerability in node-opcua, an OPC UA implementation for TypeScript and Node.js. The internal fieldsToJson method in node-opcua-client allows unsanitized field names, potentially leading to Object.prototype pollution. Successful exploitation requires an application to expose attacker-controlled event fields to fieldsToJson, which may cause denial of service or application logic corrup [truncated]