Vulnerability library
Security checkJune 11, 2026

JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

High severitynpmjs-cookie

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

js-cookie’s internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, the JSON object’s "__proto__" member is an own enumerable property, so the for…in enumerates it and the target[key] = source[key] write triggers the Object.prototype.__proto__ setter on the fresh target ({}).

Recommendation

Update the js-cookie package to the latest compatible version. Followings are version details:

  • Affected version(s): <= 3.0.5
  • Patched version(s): 3.0.7

References

Could your website be exposed too?

SmartScanner can check your website for JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated June 11, 2026