LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-31865

elysiajs · elysia

Published
CVSS6.5
Severitymedium
WeaknessCWE-1321
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Description

Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server communication. Prior to version 1.4.27, an Elysia cookie can be overridden by prototype pollution , eg. `__proto__`. This issue is patched in 1.4.27. As a workaround, use t.Cookie validation to enforce validation value and/or prevent iterable over cookie if possible.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-31865

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-31865.