Description
CASL Ability, versions 2.4.0 through 6.7.4, contains a prototype pollution vulnerability.
Recommendation
Update the @casl/ability package to the latest compatible version. Followings are version details:
- Affected version(s): >= 2.4.0, <= 6.7.4
- Patched version(s): 6.7.5
References
Could your website be exposed too?
SmartScanner can check your website for CASL Ability is Vulnerable to Prototype Pollution and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Deep Merge is Vulnerable to Prototype Pollution Through Lack of Sanitization - CVE-2026-6594
- Immutable is vulnerable to Prototype Pollution - CVE-2026-29063
- axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy` - CVE-2026-44494
- Mermaid Architecture diagrams are vulnerable to prototype pollution - CVE-2026-71437
You might also like:
See something that needs correcting? Let us knowUpdated February 11, 2026


