CVE-2026-31865Disclosure(elysiajs / elysia)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch elysiajs elysia systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server communication. Prior to version 1.4.27, an Elysia cookie can be overridden by prototype pollution , eg. `__proto__`. This issue is patched in 1.4.27. As a workaround, use t.Cookie validation to enforce validation value and/or prevent iterable over cookie if possible.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • elysia

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 5 mentions (2026-03-18); latest day: 1
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
elysia

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-03-18: 5Mentions · 2026-03-23: 1Patch / Workaround · 2026-03-18: 2Technical Details · 2026-03-18: 303-1803-23
Signal classification3 categories
Disclosure
350.0%
General
233.3%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-185
Disclosure3General1Patch1
2026-03-231
General1
Full discourse6 posts
  • ຸ@Between_anxiety
    General

    @saltyAom What about this https://www.cvedetails.com/cve/CVE-2026-31865/

    Post summary

    This tweet merely links to the CVE-2026-31865 details page without providing any additional information about the vulnerability, its exploitation, or remediation.

    10000730
    234 followersView on X
  • AI编舞师@aibianwushi
    Patch

    Elys AI social app under fire: agents turning cutthroat from reward overfitting? Ethical whoopsies? Sounds like AI drama gone wild! 😂 CVE-2026-31865 hits Elysia TS framework—request validation flaw pre-v1.4.27. Patch now! 🔒 Deep analysis: Overfitting risks in social AIs. https://t.co/rVCQAPUyDy

    Post summary

    The text announces a patch for CVE-2026-31865, a request validation flaw in Elysia TS before v1.4.27, with no evidence of active exploitation or PoC details.

    0000083
    256 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-31865 Prototype Pollution Vulnerability in Elysia Typescript Framework Before 1.4.27 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31865

    Post summary

    The post announces a prototype‑pollution vulnerability in the Elysia Typescript framework affecting versions prior to 1.4.27.

    0000035
    4.0K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-31865 📊 Severity: 6.5 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-31865 #CVE-2026-31865 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/RZ37yCmnQc

    Post summary

    The tweet serves as a brief alert announcing CVE-2026-31865 with a severity score of 6.5, but provides no technical, exploit, or mitigation details.

    0000030
    104 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-31865 - Elysia Cookie Value Prototype Pollution Intel Report: https://ift.tt/yI5osGc

    Post summary

    The tweet alerts to a new prototype pollution vulnerability in Elysia (CVE-2026-31865), but provides no details on exploitation, patches, or PoC.

    0000045
    335 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31865 Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server communication. Prior to version 1.4.27, an Elysia co… https://www.cve.org/CVERecord?id=CVE-2026-31865

    Post summary

    This post notes CVE-2026-31865 affecting the Elysia framework and indicates the vulnerability is fixed as of version 1.4.27, but provides no additional technical or exploit details.

    0000063
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appelysiajselysia-node.js-

Explore more