PatchSiren

node-opcua CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW node-opcua CVE published 2026-09-16

CVE-2026-69200

CVE-2026-69200 is a vulnerability in node-opcua, an OPC UA implementation for TypeScript and Node.js. The internal fieldsToJson method in node-opcua-client allows unsanitized field names, potentially leading to Object.prototype pollution. Successful exploitation requires an application to expose attacker-controlled event fields to fieldsToJson, which may cause denial of service or application logic corrup [truncated]