CVE-2026-33228Disclosure(webreflection / flatted)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the internal input buffer is a JavaScript Array, accessing it with the key "__proto__" returns Array.prototype via the inherited getter. This object is then treated as a legitimate parsed value and assigned as a property of the output object, effectively leaking a live reference to Array.prototype to the consumer. Any code that subsequently writes to that property will pollute the global prototype. This issue has been patched in version 3.4.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321CWE-915

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flatted

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-21); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
flatted

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-21: 1Mentions · 2026-03-23: 1Technical Details · 2026-03-21: 1Technical Details · 2026-03-23: 103-2103-23
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-33228 - Critical flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, witho... https://www.thehackerwire.com/vulnerability/CVE-2026-33228/ https://t.co/EitPKqKtfF

    Post summary

    The post alerts to a critical flaw in flatted's parse() function that lets attacker-controlled strings become array indices, but it provides no exploit evidence or patch guidance.

    0000028
    145 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33228 flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct ar… https://www.cve.org/CVERecord?id=CVE-2026-33228

    Post summary

    The post announces CVE-2026-33228, indicating that before v3.4.2 the flatted JSON parser’s parse() function can interpret attacker‑controlled string values, implying a potential vulnerability. No PoC, exploit, patch, or active exploitation is referenced.

    00000102
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwebreflectionflatted-node.js-

Explore more