PatchSiren

thomaspoignant CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL thomaspoignant CVE published 2026-08-07

CVE-2026-48170

A critical vulnerability in the `scim-patch` library prior to version 0.9.1 allows for prototype pollution when applying a SCIM PATCH operation with a maliciously crafted `value` object. This issue can lead to the modification of `Object.prototype` process-wide, affecting every plain object in the Node process. Services calling `scimPatch()` on attacker-controlled JSON, particularly those exposed to exter [truncated]