CVE-2026-67321: Unchecked Config Property Prototype Pollution

Direct access to configuration properties without checking for own-property existence allows prototype pollution gadgets to inject unexpected parameters into requests.

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0JS
greprules fetch cve-2026-67321-unchecked-config-property-prototype-pollution --engine opengrep

Description

Direct access to configuration properties without checking for own-property existence allows prototype pollution gadgets to inject unexpected parameters into requests.