mediumVulnerability
CVE-2026-85063
### Impact With columns: true and group_columns_by_name: true, a duplicated __proto__ header causes the duplicate-column branch to assign an array to obj['__proto__'], invoking the __proto__ setter and replacing the parsed record object's prototype with attacker-controlled data. Fixed in 7.0.2 (Object.hasOwn duplicate check + Object.defineProperty assignment). ### Patches The problem been patched. ### Workarounds Disable usage of both the columns and group_columns_by_name options. ### References issue #496, PR #497
Properties
- ghsa_id
- GHSA-8cw4-87c7-c6xx
- severity
- medium
- summary
- node-csv: Prototype replacement still reachable via columns path
- epss_score
- 0.00325
- cve_id
- CVE-2026-85063
- is_ghsa_only
- false
- ghsa_published
- 2026-09-08T18:01:39Z
- source_url
- https://github.com/advisories/GHSA-8cw4-87c7-c6xx
- epss_percentile
- 0.25224
- ghsa_updated
- 2026-09-08T18:01:41Z
Related Entities (5)
ENRICHED_BY (1)
→[Source]FIRST EPSS
VULNERABLE_TO (1)
←[Software]npm/csv-parse
AFFECTS (1)
→[Software]npm/csv-parse
HAS_WEAKNESS (1)
→[Weakness]Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph