mcp-data-vis vulnerable to denial of service via unsanitized `select` key lookup on `Object.prototype` with `precompile:
- Severity:
- Low
Description
icu-minify’s runtime formatter resolves select branches by looking up the runtime value as a plain property on a prototype-bearing object. When the value coerces to a key that exists on Object.prototype (e.g.
Recommendation
Update the icu-minify package to the latest compatible version. Followings are version details:
- Affected version(s): <= 4.9.1
- Patched version(s): 4.9.2
References
Related Issues
- Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig - CVE-2026-25639
- path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters - CVE-2026-4867
- path-to-regexp vulnerable to Denial of Service via sequential optional groups - CVE-2026-4926
- path-to-regexp vulnerable to Regular Expression Denial of Service via multiple wildcards - CVE-2026-4923
You might also like:
- Tags:
- npm
- icu-minify
Anything's wrong? Let us know Last updated on May 06, 2026


