External risk intelligence

Yayson Prototype Pollution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-61534

Yayson is a JavaScript library used by developers to handle JSON:API data. While libraries are often used in web applications that may be internet-facing, the library itself is an internal dependency. Reachability depends entirely on how the consuming application processes untrusted input, and the library is not inherently an edge service, gateway, or public-facing appliance.

Denial of Service

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability exists in the Yayson JavaScript library that could allow an attacker to modify the application's core behavior, potentially leading to denial of service or logic corruption.

  • Yayson library allows prototype pollution.
  • Affects JavaScript applications handling JSON:API data.
  • Confirm relevance and potential exposure of Yayson usage.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending specially crafted JSON:API data to an application that uses the Yayson library. If the application processes this data without proper sanitization, the attacker can manipulate type, id, or relationship names within the JSON to inject malicious properties into JavaScript's global Object.prototype. This can lead to the modification of application behavior.

  • No authentication required.
  • Malicious JSON input processed by Store or LegacyStore.
  • Process-wide prototype pollution leading to denial of service or logic corruption.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, an attacker could corrupt the application's behavior by manipulating JSON:API type, id, or relationship names. This could lead to denial of service or logic corruption within the application.

  • Application code and runtime state.
  • Malicious JSON data processed by the application.
  • Denial of service or logic corruption.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Yayson library's prototype pollution vulnerability requires immediate attention from application owners and development teams. First, identify all instances where Yayson is integrated into your JavaScript applications. Confirm whether these applications process external input that could be manipulated to exploit the vulnerability, particularly concerning the `__proto__`, `constructor`, or `prototype` properties in JSON:API data. Once identified and confirmed as reachable, plan remediation by coordinating with development and vendor management teams to upgrade Yayson or implement compensating controls.

  • Application owners must prioritize this issue.
  • Verify external input processing via Yayson.
  • Plan Yayson upgrades or mitigation strategies.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Yayson library?

Yayson is a JavaScript library designed to simplify the serialization and deserialization of JSON:API data. Developers integrate it into their web applications to map complex data structures between JSON and local object models, making it easier to manage resource types, identifiers, and relationships within a JavaScript environment.

What does CVE-2026-61534 mean by prototype pollution?

This vulnerability falls under the Weakness Class CWE-1321. In JavaScript, prototype pollution occurs when an attacker can inject properties into the base 'Object' template that all other objects inherit. By sending specially crafted JSON:API data, an attacker forces the library to overwrite core system definitions, which can unpredictably alter how the entire application behaves.

How can an attacker trigger this vulnerability?

The bug is triggered when the library processes malicious JSON:API input containing specific keys like __proto__, constructor, or prototype within the type, id, or relationship fields. It does not trigger if the application only processes trusted, internal data sources or if the library is not used to parse untrusted user-provided JSON structures.

Is my application at risk if Yayson is installed?

According to Halo Surface Signal, risk depends on how your application uses the library. Because Yayson is an internal dependency rather than a public-facing appliance, the primary risk is for applications that accept and process untrusted input from external users. You should focus on identifying web services that pass external JSON:API payloads directly into Yayson's Store or LegacyStore components.

How do I fix this issue in my project?

The primary solution is to upgrade the Yayson library to version 4.3.0 or later, which includes the necessary security fixes. Start by auditing your codebase to locate all dependencies on Yayson. If an immediate upgrade is not feasible, work with your development team to implement strict input validation to ensure that no incoming JSON:API data contains prohibited property names like __proto__.

References