PT-2026-28612 · Mikroorm · Mikroorm

Lukas-Eu

·

Published

2026-03-29

·

Updated

2026-04-04

·

CVE-2026-34221

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions MikroORM versions prior to 6.6.10 MikroORM versions prior to 7.0.6
Description A flaw exists in the Utils.merge helper within MikroORM that does not prevent the use of special keys like proto, constructor, and prototype during object merging. This allows attacker-controlled input to potentially modify the JavaScript object prototype. Exploitation requires application code to pass untrusted user input into ORM operations that merge object structures, such as entity property assignment or query condition construction. Prototype pollution may lead to denial of service or unexpected application behavior. In some cases, polluted properties could influence query construction, potentially resulting in SQL injection depending on the application code.
Recommendations Update to MikroORM version 6.6.10 or later. Update to MikroORM version 7.0.6 or later.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2026-34221
GHSA-QPFV-44F3-QQX6

Affected Products

Mikroorm