{"id":"CVE-2026-1774","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-1774","summary":"CASL Ability is Vulnerable to Prototype Pollution","details":"CASL Ability, versions 2.4.0 through 6.7.4, contains a prototype pollution vulnerability.","published":"2026-02-10T18:30:38Z","modified":"2026-02-11T19:26:17.624339Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@casl/ability","fixedVersion":"6.7.5"}],"fix":{"url":"https://github.com/stalniy/casl/pull/1093","label":"stalniy/casl#1093"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-1774"},{"type":"WEB","url":"https://github.com/stalniy/casl/pull/1093"},{"type":"WEB","url":"https://github.com/stalniy/casl/commit/39da920ec1dfadf3655e28bd0389e960ac6871f4"},{"type":"WEB","url":"https://cwe.mitre.org/data/definitions/1321.html"},{"type":"WEB","url":"https://developer.mozilla.org/en-US/docs/Web/Security/Attacks/Prototype_pollution"},{"type":"PACKAGE","url":"https://github.com/stalniy/casl"},{"type":"WEB","url":"https://github.com/stalniy/casl/tree/master/packages/casl-ability"},{"type":"WEB","url":"https://www.kb.cert.org/vuls/id/458422"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-11T19:26:17.624339Z"}}