CVE-2026-1774
CASL Ability, versions 2.4.0 through 6.7.4, contains a prototype pollution vulnerability.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2026-1774, https://github.com/stalniy/casl/pull/1093, https://github.com/stalniy/casl/commit/39da920ec1dfadf3655e28bd0389e960ac6871f4, https://cwe.mitre.org/data/definitions/1321.html, https://developer.mozilla.org/en-US/docs/Web/Security/Attacks/Prototype_pollution, https://github.com/stalniy/casl, https://github.com/stalniy/casl/tree/master/packages/casl-ability, https://www.kb.cert.org/vuls/id/458422
