A medium severity vulnerability affecting scim-patch versions < 0.9.2, CVE-2026-61834 with a CVSS score of 4.3, exists in the scim-patch package where an attacker controlling a SCIM PATCH operation can use paths such as toString.polluted to mutate shared built-in function objects by adding attacker-controlled properties to inherited built-in method objects that are process-global and may affect application logic reading properties from inherited methods due to traversing inherited properties when applying patch paths. This vulnerability occurs because scim-patch blocks direct dangerous path segments but still follows inherited properties, allowing an attacker to manipulate shared built-in function objects such as Object.prototype.toString. The impact is narrower than direct Object.prototype pollution but the mutation is process-global and may affect application logic reading properties from inherited methods. The flaw type is CWE-915, CWE-1321, with an attack vector of AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N and a business impact of potential data tampering or manipulation through SCIM patch operations.
We recommend you to update scim-patch to version 0.9.2.[/subscribe_to_unlock_form]
A medium severity vulnerability affecting scim-patch versions < 0.9.2, CVE-2026-61834 with a CVSS score of 4.3, exists in the scim-patch package where an attacker controlling a SCIM PATCH operation can use paths such as toString.polluted to mutate shared built-in function objects by adding attacker-controlled properties to inherited built-in method objects that are process-global and may affect application logic reading properties from inherited methods due to traversing inherited properties when applying patch paths. This vulnerability occurs because scim-patch blocks direct dangerous path segments but still follows inherited properties, allowing an attacker to manipulate shared built-in function objects such as Object.prototype.toString. The impact is narrower than direct Object.prototype pollution but the mutation is process-global and may affect application logic reading properties from inherited methods. The flaw type is CWE-915, CWE-1321, with an attack vector of AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N and a business impact of potential data tampering or manipulation through SCIM patch operations.
We recommend you to update scim-patch to version 0.9.2.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]