CVE-2026-28794Disclosure(orpc / orpc)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1.13.6, a prototype pollution vulnerability exists in the RPC JSON deserializer of the @orpc/client package. The vulnerability allows unauthenticated, remote attackers to inject arbitrary properties into the global Object.prototype. Because this pollution persists for the lifetime of the Node.js process and affects all objects, it can lead to severe security breaches, including authentication bypass, denial of service, and potentially Remote Code Execution. This issue has been patched in version 1.13.6.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • orpc

Threat summary

  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 3 classified signals
  • Peaked 2d ago at 4 mentions (2026-03-06); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
orpc

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-03-06: 4Mentions · 2026-03-07: 1Mentions · 2026-03-11: 1Technical Details · 2026-03-06: 4Technical Details · 2026-03-11: 103-0603-0703-11
Signal classification2 categories
Disclosure
350.0%
General
350.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-064
Disclosure3General1
2026-03-071
General1
2026-03-111
General1
Full discourse6 posts
  • dmesg -w | grep mixdev@usrbinmix
    General

    CVE-2026-28794, 9.3/10 https://t.co/eyi9k9NGQy

    Post summary

    The tweet merely cites CVE-2026-28794 with a CVSS score of 9.3/10, offering no evidence of PoC, exploitation, or remediation.

    0201413.8K
    1.6K followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-28794 (CVSS:9.3, CRITICAL) is Analyzed. oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1...https://nvd.nist.gov/vuln/detail/CVE-2026-28794 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post cites CVE-2026‑28794 as a critical vulnerability by CVSS score, but provides no PoC, exploit details, active exploitation notice, or patch information.

    0001027
    172 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-28794 oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1.13.6, a prototype pollution vulnerability exis… https://www.cve.org/CVERecord?id=CVE-2026-28794 ----- Traducción: CVE-2026-28794 oRP… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑28794, noting a prototype pollution flaw in oRPC before v1.13.6, without mentioning PoC, exploit code, active attacks, or patches.

    0001034
    56 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-28794 oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1.13.6, a prototype pollution vulnerability exis… https://www.cve.org/CVERecord?id=CVE-2026-28794

    Post summary

    The post reports a prototype‑pollution vulnerability in oRPC prior to version 1.13.6 and directs readers to the CVE record for more details.

    00010159
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28794 Prototype Pollution Vulnerability in oRPC @orpc/client Package Before 1.13.6 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28794

    Post summary

    The post announces a prototype pollution vulnerability in the @orpc/client package prior to version 1.13.6, providing basic technical details but no evidence of exploitation or remediation.

    0001046
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-28794 - oRPC: Prototype Pollution in `@orpc/client` via `StandardRPCJsonSerializer` Deserialization Intel Report: https://ift.tt/qVb9SRU

    Post summary

    The alert announces CVE‑2026‑28794, a prototype‑pollution vulnerability in @orpc/client triggered by deserialization through StandardRPCJsonSerializer, and references an Intel report for additional details.

    0000045
    343 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apporpcorpc---

Explore more