
CVE-2026-48170 - Critical prototype pollution in scim-patch <0.9.1. Attacker-controlled SCIM PATCH can pollute Object.prototype process-wide. CVSS 9.1. Unpatched - update immediately. #CVE #NodeJS #infosec https://www.valtersit.com/cve/CVE-2026-48170 #infosec #cybersecurity #CVE #Linux #infosec #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu
Post summary
This tweet announces CVE‑2026‑48170, a critical prototype‑pollution flaw in scim‑patch versions below 0.9.1 that can pollute Object.prototype process‑wide. The vulnerability carries a CVSS score of 9.1 and remains unpatched, urging immediate update.





