Unsafe-deserialization chain in popular Node logging library — CVE-2026-12345
A JSON sink in the structured-log transformer accepted attacker-controlled type tags, allowing remote code execution through a prototype-pollution gadget chained into the library's plugin loader. Reachable from any service that logged a request body before sanitisation. Patched in the maintainer's 4.2.1 release with a strict type allowlist; coordinated disclosure window was honoured to the day.
Read full disclosure