mediumVulnerability

CVE-2026-85063

### Impact With columns: true and group_columns_by_name: true, a duplicated __proto__ header causes the duplicate-column branch to assign an array to obj['__proto__'], invoking the __proto__ setter and replacing the parsed record object's prototype with attacker-controlled data. Fixed in 7.0.2 (Object.hasOwn duplicate check + Object.defineProperty assignment). ### Patches The problem been patched. ### Workarounds Disable usage of both the columns and group_columns_by_name options. ### References issue #496, PR #497

Properties

ghsa_id
GHSA-8cw4-87c7-c6xx
severity
medium
summary
node-csv: Prototype replacement still reachable via columns path
epss_score
0.00325
cve_id
CVE-2026-85063
is_ghsa_only
false
ghsa_published
2026-09-08T18:01:39Z
source_url
https://github.com/advisories/GHSA-8cw4-87c7-c6xx
epss_percentile
0.25224
ghsa_updated
2026-09-08T18:01:41Z

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (1)

[Software]npm/csv-parse

AFFECTS (1)

[Software]npm/csv-parse

HAS_WEAKNESS (1)

[Weakness]Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-85063 — Ninja Signal Threat Intelligence | Ninja Signal