CVE-2026-59724: Engine Unsafe Prototype Lookup Dos

Object property lookup using an unvalidated key allows built-in prototype properties (e.g., `__proto__`) to bypass simple truthiness checks. If the resolved inherited object is used improperly, this can lead to unhandled exceptions and Denial of Service (DoS). Validate that the property exists directly on the object using `Object.hasOwn()`, `.hasOwnProperty.

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0JS
greprules fetch cve-2026-59724-engine-unsafe-prototype-lookup-dos --engine opengrep

Description

Object property lookup using an unvalidated key allows built-in prototype properties (e.g., `__proto__`) to bypass simple truthiness checks. If the resolved inherited object is used improperly, this can lead to unhandled exceptions and Denial of Service (DoS). Validate that the property exists directly on the object using `Object.hasOwn()`, `.hasOwnProperty.