CRITICAL
thomaspoignant
CVE published 2026-08-07
CVE-2026-48170
A critical vulnerability in the `scim-patch` library prior to version 0.9.1 allows for prototype pollution when applying a SCIM PATCH operation with a maliciously crafted `value` object. This issue can lead to the modification of `Object.prototype` process-wide, affecting every plain object in the Node process. Services calling `scimPatch()` on attacker-controlled JSON, particularly those exposed to exter [truncated]