{"id":"CVE-2026-55886","aliases":["GHSA-vpmm-x3fm-qr5c"],"url":"https://o3.security/vulnerability/CVE-2026-55886","summary":"Jodit Editor: Prototype Pollution in Jodit via Jodit.modules.Helpers.set()","details":"Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities. Versions prior to 4.12.26 are vulnerable to Prototype Pollution through Jodit.modules.Helpers.set(chain, value, obj), which walks the dot-separated chain, creating and following each path segment without filtering prototype-mutating keys. A chain that begins with (or contains) __proto__, constructor, or prototype lets the final assignment reach and mutate Object.prototype. Applications that pass a user-controlled or partially user-controlled key path into Jodit.modules.Helpers.set() could be vulnerable, causing unexpected property injection, logic bypass, denial of service, or secondary security issues. This issue has been fixed in version 4.12.26.","published":"2026-07-01T20:25:43.632Z","modified":"2026-08-12T03:51:21.877834590Z","cvss":null,"epss":{"score":0.00534,"percentile":0.43483,"asOf":"2026-09-12"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"jodit","fixedVersion":"4.12.26"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55886.json"},{"type":"ADVISORY","url":"https://github.com/xdan/jodit/security/advisories/GHSA-vpmm-x3fm-qr5c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55886"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:21.877834590Z"}}