Intel

AIKIDO-2026-10487

ast-walker-scope is vulnerable to Prototype Pollution

Prototype Pollution Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

62

Medium Risk

This Affects:

JSast-walker-scope
0.0.1 - 0.8.3
Fixed in 0.9.0

TL;DR

Affected versions of this package are vulnerable to Prototype Pollution due to insufficient validation of user-supplied input, allowing attackers to inject malicious properties like __proto__. An attacker could exploit this by manipulating these operations to modify the prototype of base objects, potentially leading to arbitrary code execution, denial of service, or privilege escalation.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

ast-walker-scope is vulnerable to Prototype Pollution in versions 0.0.1 - 0.8.3.

How to fix this

Upgrade the ast-walker-scope library to a patch version.