CVE-2026-24888Disclosure(microsoft / maker.js)

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Maker.js is a 2D vector line drawing and shape modeling for CNC and laser cutters. In versions up to and including 0.19.1, the `makerjs.extendObject` function copies properties from source objects without proper validation, potentially exposing applications to security risks. The function lacks `hasOwnProperty()` checks and does not filter dangerous keys, allowing inherited properties and potentially malicious properties to be copied to target objects. A patch is available in commit 85e0f12bd868974b891601a141974f929dec36b8, which is expected to be part of version 0.19.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • maker.js

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
maker.js

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-01-28: 3Technical Details · 2026-01-28: 201-28
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24888 Prototype Pollution Vulnerability in Maker.js Vector Library Before 0.19.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24888

    Post summary

    The entry announces CVE-2026-24888 as a prototype‑pollution flaw in Maker.js Vector Library versions older than 0.19.2, without indicating PoC, exploit, or remediation details.

    0000053
    4.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    ⚡ CVE-2026-24888: Maker.js Vulnerable to Unsafe Pr... Prototype pollution in Maker.js extendObject() lets attackers inject properties into target objects, potentially enabli... https://zerodaysignal.com/vulnerability/CVE-2026-24888 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE‑2026‑24888 is a prototype‑pollution flaw in Maker.js’s extendObject() that allows attackers to inject properties into target objects. The post supplies technical details but does not mention a PoC, exploit, active use, patch, or debunking.

    00000100
    132 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24888 Maker.js is a 2D vector line drawing and shape modeling for CNC and laser cutters. In versions up to and including 0.19.1, the `makerjs.extendObject` function copies … https://www.cve.org/CVERecord?id=CVE-2026-24888

    Post summary

    The snippet announces CVE-2026-24888 affecting Maker.js versions up to 0.19.1, noting an issue with the `makerjs.extendObject` function, but offers no further technical details or exploit information.

    00000254
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftmaker.js-node.js-

Explore more