Vulnerability record · CVE-2019-11358 · published 20 April 2019
CVE-2019-11358: jQuery extend() prototype pollution via unsanitized __proto__
Jquery · Jquery
jQuery before 3.4.0 mishandles jQuery.extend(true, {}, ...) so that an unsanitized source object containing an enumerable __proto__ property can extend the native Object.prototype. This prototype pollution affects jQuery itself and products embedding it, including Drupal, Backdrop CMS, and numerous enterprise applications. Because the vulnerable library is widely bundled, the flaw has a very large installed base even though the direct impact per instance is limited.
Description
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityThe direct CVSS impact is medium and requires user interaction, but the extremely high EPSS score and the very broad set of affected products make this a high-priority dependency to remediate.
What it is
jQuery before 3.4.0 mishandles jQuery.extend(true, {}, ...) so that an unsanitized source object containing an enumerable __proto__ property can extend the native Object.prototype. This prototype pollution affects jQuery itself and products embedding it, including Drupal, Backdrop CMS, and numerous enterprise applications. Because the vulnerable library is widely bundled, the flaw has a very large installed base even though the direct impact per instance is limited.
Impact
An attacker can pollute Object.prototype, altering application behavior and potentially enabling client-side script execution or logic bypass in affected pages. The CVSS vector rates confidentiality and integrity impact as low, so the direct gain is limited but can be chained with other flaws.
Attack surface
Reached over the network through a crafted object passed to jQuery.extend(true, {}, ...), typically via a web page or application input. The CVSS vector requires user interaction (UI:R) and no privileges (PR:N), so a victim must load or interact with attacker-influenced content.
Exploitation
Not listed in CISA KEV and no ransomware groups are documented using it, but EPSS is very high (0.87218, 99.7th percentile), indicating strong predicted exploitation activity; references include patch and vendor advisory tags.
What to do
- Upgrade jQuery to 3.4.0 or later, or apply the vendor patch commit 753d591aea698e57d6db58c9f722cd0808619b1b.
- Update or patch downstream products that bundle jQuery (Drupal, Backdrop CMS, and other listed vendors) per their security advisories.
- Avoid passing untrusted objects into jQuery.extend(true, {}, ...) and sanitize or reject keys such as __proto__ and constructor.prototype.
- Use a software composition analysis or RetireJS-style scan to find bundled jQuery versions below 3.4.0 across web applications.
- Where immediate upgrade is not possible, apply vendor backports or compensating input validation at the application layer.
Detection
- Scan web assets and JavaScript bundles for jQuery versions below 3.4.0.
- Monitor application logs and client-side telemetry for requests or payloads containing __proto__ or constructor.prototype keys.
- Review dependency manifests and SBOMs for the affected products and vendors listed in the record.
- Track vendor advisories and errata for the listed products to confirm patched versions are deployed.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
105 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-11358 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-11358), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.