Description
Elysia cookie can be overridden by prototype pollution , eg. __proto__
Recommendation
Update the elysia package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.4.27
- Patched version(s): 1.4.27
References
Could your website be exposed too?
SmartScanner can check your website for Elysia Cookie Value Prototype Pollution and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Mermaid configuration APIs allow prototype pollution - CVE-2026-71438
- JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection - CVE-2026-46625
- Mermaid Architecture diagrams are vulnerable to prototype pollution - CVE-2026-71437
- CASL Ability is Vulnerable to Prototype Pollution - CVE-2026-1774
You might also like:
See something that needs correcting? Let us knowUpdated March 22, 2026


