MEDIUM 5.0 GitHub
CVE-2026-57439
CyberChef: Prototype pollution in Series Chart operation
On 5 June 2026 CyberChef received a security vulnerability report from @hyuunnn detailing a vulnerability in the Series Chart operation, where malicious input could result in prototype pollution of the data structures outputted from the operation.
Other operations following Series Chart could have their behaviour manipulated by the attacker-controlled prototype, for example, injecting malicious content into their HTML output.
In this case, a demonstration was provided that chained the Series Ch
Affected Products
- npm/cyberchef < 11.2.0
References
- https://github.com/advisories/GHSA-fx6f-382r-j72c
- https://github.com/gchq/CyberChef/security/advisories/GHSA-fx6f-382r-j72c
- https://nvd.nist.gov/vuln/detail/CVE-2026-57439
- https://github.com/gchq/CyberChef/issues/2568
This medium severity vulnerability with a CVSS score of 5.0 was published on 2026-09-24 via GitHub. Affected: npm/cyberchef < 11.2.0.
vulnfeed aggregates 11711 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.