CVE-2026-28794 is a critical prototype pollution vulnerability in the @orpc/client package (versions prior to 1.13.6) of the oRPC tool, allowing unauthenticated remote attackers to inject arbitrary properties into the global Object.prototype. This vulnerability carries a CVSS score of 9.3 (CRITICAL) due to its network attack vector, low complexity, and potential for severe impacts including authentication bypass, denial of service, and remote code execution. While there are no known active exploits, public exploit code, or KEV entries, the issue has garnered some community attention, with one mention on Mastodon highlighting its critical nature. Organizations using affected versions should upgrade to 1.13.6 or later immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.13.6CPE matchmatch criteria | cpe:2.3:a:orpc:orpc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.