CVE-2026-33228 is a critical vulnerability affecting versions of the 'flatted' circular JSON parser prior to 3.4.2. This flaw allows an attacker to inject specific string values as array indices during parsing, leading to global prototype pollution by leaking and modifying Array.prototype. Rated 9.8 Critical on the CVSS scale, it presents a severe risk with a network attack vector, low attack complexity, and no required privileges or user interaction, potentially impacting confidentiality, integrity, and availability. Despite its critical severity, there is currently no evidence of active exploitation, nor are public exploits available in Metasploit, Nuclei, or ExploitDB. Community discussion is minimal, and its very low EPSS score suggests a low probability of exploitation in the wild. Organizations using affected versions should update to 3.4.2 or later to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.4.2CPE matchmatch criteria | cpe:2.3:a:webreflection:flatted:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.