All vulnerability reports

Prototype pollution in chart configuration and component i18n

Overview

The deep merge helpers in Vaadin Charts and in the i18n support of Vaadin components copy properties without filtering keys that address the prototype chain, so merging data the application does not control can add properties to Object.prototype and make them visible to every object in the running application.


See CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Description

Both @vaadin/charts and the I18nMixin in @vaadin/component-base carry a recursive merge helper that copies properties from a caller supplied object into a target object without filtering keys that address the prototype chain. A __proto__ key whose value is an object therefore writes onto Object.prototype, and because every ordinary JavaScript object inherits from it, the injected properties become visible throughout the application. This can corrupt application logic, cause a denial of service, or act as a gadget for further attacks.

The vulnerability is reached where an application assigns an object it did not construct itself, typically one parsed from JSON, to the i18n property of a component, to the additionalOptions property of <vaadin-chart> or <vaadin-chart-series>, or to updateConfiguration() of <vaadin-chart>. No special configuration is required.

Applications using the Java (Flow) API are not affected through the setI18n() APIs or the chart Configuration model, because the property names sent to the client originate from typed Java models. The one exception is Exporting.setMenuItemDefinitions(), whose map keys are supplied by the application.

The i18n merge was introduced in Vaadin 24.7.0, so versions before that are affected through Vaadin Charts only.

Affected products and mitigation

Users of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include:

Product version Mitigation
Vaadin 23.0.0 - 23.6.13
Upgrade to 23.6.14
Vaadin 24.0.0 - 24.9.20
Upgrade to 24.9.21
Vaadin 24.10.0 - 24.10.9
Upgrade to 24.10.10
Vaadin 25.0.0 - 25.1.11
Upgrade to 25.1.12
Vaadin 25.2.0 - 25.2.6
Upgrade to 25.2.7 or newer

Please note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 23, 24, 25 version.

Artifacts

Maven coordinates Vulnerable version Fixed version
com.vaadin:vaadin
23.0.0 - 23.6.13
≥23.6.14
com.vaadin:vaadin
24.0.0 - 24.9.20
≥24.9.21
com.vaadin:vaadin
24.10.0 - 24.10.9
≥24.10.10
com.vaadin:vaadin
25.0.0 - 25.1.11
≥25.1.12
com.vaadin:vaadin
25.2.0 - 25.2.6
≥25.2.7
com.vaadin:vaadin-core
24.7.0 - 24.9.20
≥24.9.21
com.vaadin:vaadin-core
24.10.0 - 24.10.9
≥24.10.10
com.vaadin:vaadin-core
25.0.0 - 25.1.11
≥25.1.12
com.vaadin:vaadin-core
25.2.0 - 25.2.6
≥25.2.7
com.vaadin:vaadin-charts-flow
23.0.0 - 23.6.13
≥23.6.14
com.vaadin:vaadin-charts-flow
24.0.0 - 24.9.20
≥24.9.21
com.vaadin:vaadin-charts-flow
24.10.0 - 24.10.9
≥24.10.10
com.vaadin:vaadin-charts-flow
25.0.0 - 25.1.11
≥25.1.12
com.vaadin:vaadin-charts-flow
25.2.0 - 25.2.6
≥25.2.7

com.vaadin:vaadin-core is affected from 24.7.0 onwards only: Vaadin Charts is not part of Vaadin core, so an application using core alone is exposed through the i18n merge, which was introduced in 24.7.0.

npm package Vulnerable version Fixed version
@vaadin/charts
23.0.0 - 23.6.4
≥23.6.5
@vaadin/charts
24.0.0 - 24.9.17
≥24.9.18
@vaadin/charts
24.10.0 - 24.10.4
≥24.10.5
@vaadin/charts
25.0.0 - 25.1.11
≥25.1.12
@vaadin/charts
25.2.0 - 25.2.8
≥25.2.9
@vaadin/component-base
24.7.0 - 24.9.17
≥24.9.18
@vaadin/component-base
24.10.0 - 24.10.4
≥24.10.5
@vaadin/component-base
25.0.0 - 25.1.11
≥25.1.12
@vaadin/component-base
25.2.0 - 25.2.8
≥25.2.9

The npm versions are the web components versions and do not match the Vaadin product versions.

References

https://github.com/vaadin/web-components/pull/12483

Credit

Reported by Ridwan Arefin Islam - Madiba Security Lab, Concordia University.

History

  • 2026-09-30: Initial vulnerability report published