Elysia Cookie Value Prototype Pollution
Description
Published to the GitHub Advisory Database
Mar 17, 2026
Reviewed
Mar 17, 2026
Published by the National Vulnerability Database
Mar 18, 2026
Last updated
Mar 22, 2026
Impact
Elysia cookie can be overridden by prototype pollution , eg.
__proto__Sending cookie with the follows name can override cookie value:
Patches
Patched by 1.4.27
Workarounds
References