Prototype pollution in chart configuration and component i18n
Overview
See CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Description
__proto__ key whose value is an object therefore writes onto Object.prototype, and because every ordinary JavaScript object inherits from it, the injected properties become visible throughout the application. This can corrupt application logic, cause a denial of service, or act as a gadget for further attacks.
The vulnerability is reached where an application assigns an object it did not construct itself, typically one parsed from JSON, to the i18n property of a component, to the additionalOptions property of <vaadin-chart> or <vaadin-chart-series>, or to updateConfiguration() of <vaadin-chart>. No special configuration is required.
Applications using the Java (Flow) API are not affected through the setI18n() APIs or the chart Configuration model, because the property names sent to the client originate from typed Java models. The one exception is Exporting.setMenuItemDefinitions(), whose map keys are supplied by the application.
The i18n merge was introduced in Vaadin 24.7.0, so versions before that are affected through Vaadin Charts only.
Affected products and mitigation
Users of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include:
| Product version | Mitigation |
|---|---|
|
Vaadin 23.0.0 - 23.6.13
|
Upgrade to 23.6.14
|
|
Vaadin 24.0.0 - 24.9.20
|
Upgrade to 24.9.21
|
|
Vaadin 24.10.0 - 24.10.9
|
Upgrade to 24.10.10
|
|
Vaadin 25.0.0 - 25.1.11
|
Upgrade to 25.1.12
|
|
Vaadin 25.2.0 - 25.2.6
|
Upgrade to 25.2.7 or newer
|
Please note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 23, 24, 25 version.
Artifacts
| Maven coordinates | Vulnerable version | Fixed version |
|---|---|---|
|
com.vaadin:vaadin
|
23.0.0 - 23.6.13
|
≥23.6.14
|
|
com.vaadin:vaadin
|
24.0.0 - 24.9.20
|
≥24.9.21
|
|
com.vaadin:vaadin
|
24.10.0 - 24.10.9
|
≥24.10.10
|
|
com.vaadin:vaadin
|
25.0.0 - 25.1.11
|
≥25.1.12
|
|
com.vaadin:vaadin
|
25.2.0 - 25.2.6
|
≥25.2.7
|
|
com.vaadin:vaadin-core
|
24.7.0 - 24.9.20
|
≥24.9.21
|
|
com.vaadin:vaadin-core
|
24.10.0 - 24.10.9
|
≥24.10.10
|
|
com.vaadin:vaadin-core
|
25.0.0 - 25.1.11
|
≥25.1.12
|
|
com.vaadin:vaadin-core
|
25.2.0 - 25.2.6
|
≥25.2.7
|
|
com.vaadin:vaadin-charts-flow
|
23.0.0 - 23.6.13
|
≥23.6.14
|
|
com.vaadin:vaadin-charts-flow
|
24.0.0 - 24.9.20
|
≥24.9.21
|
|
com.vaadin:vaadin-charts-flow
|
24.10.0 - 24.10.9
|
≥24.10.10
|
|
com.vaadin:vaadin-charts-flow
|
25.0.0 - 25.1.11
|
≥25.1.12
|
|
com.vaadin:vaadin-charts-flow
|
25.2.0 - 25.2.6
|
≥25.2.7
|
com.vaadin:vaadin-core is affected from 24.7.0 onwards only: Vaadin Charts is not part of Vaadin core, so an application using core alone is exposed through the i18n merge, which was introduced in 24.7.0.
| npm package | Vulnerable version | Fixed version |
|---|---|---|
|
@vaadin/charts
|
23.0.0 - 23.6.4
|
≥23.6.5
|
|
@vaadin/charts
|
24.0.0 - 24.9.17
|
≥24.9.18
|
|
@vaadin/charts
|
24.10.0 - 24.10.4
|
≥24.10.5
|
|
@vaadin/charts
|
25.0.0 - 25.1.11
|
≥25.1.12
|
|
@vaadin/charts
|
25.2.0 - 25.2.8
|
≥25.2.9
|
|
@vaadin/component-base
|
24.7.0 - 24.9.17
|
≥24.9.18
|
|
@vaadin/component-base
|
24.10.0 - 24.10.4
|
≥24.10.5
|
|
@vaadin/component-base
|
25.0.0 - 25.1.11
|
≥25.1.12
|
|
@vaadin/component-base
|
25.2.0 - 25.2.8
|
≥25.2.9
|
The npm versions are the web components versions and do not match the Vaadin product versions.
References
https://github.com/vaadin/web-components/pull/12483
Credit
Reported by Ridwan Arefin Islam - Madiba Security Lab, Concordia University.
History
- 2026-09-30: Initial vulnerability report published