PatchSiren

StableLib CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH StableLib CVE published 2026-04-04

CVE-2026-106448

CVE-2026-106448 is a high-severity vulnerability in StableLib, a TypeScript and JavaScript library. The vulnerability allows for prototype poisoning via __proto__ map keys in CBOR decoding, potentially leading to security-sensitive decisions being made using inherited attacker data. This issue affects applications using StableLib versions prior to 2.0.4. Defenders should assess exposure and prioritize ver [truncated]