Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-46625
js-cookie js-cookie — JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U N H N 7.5 .0099 61.1 —
AFFECTED
Product Versions Fixed
js-cookie < 3.0.7 – —
TIMELINE
May 15 Reserved by GitHub_M
Jun 10 Published (CNA: GitHub_M)
Aug 26 EXPLOIT PUBLISHED — CVE-2026-46625 (js-cookie). Public exploit reference added.
Aug 28 EXPLOIT PUBLISHED — CVE-2026-46625 (js-cookie). Public exploit reference added.
Sep 4 EXPLOIT PUBLISHED — CVE-2026-46625 (js-cookie). Public exploit reference added.
Sep 7 EXPLOIT PUBLISHED — CVE-2026-46625 (js-cookie). Public exploit reference added.
Sep 9 EXPLOIT PUBLISHED — CVE-2026-46625 (js-cookie). Public exploit reference added.
Description
JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, the JSON object's "__proto__" member is an own enumerable property, so the for…in enumerates it and the target[key] = source[key] write triggers the Object.prototype.__proto__ setter on the fresh target ({}). The result is a per-instance prototype hijack: Object.prototype itself is untouched, but the merged attributes object now inherits attacker-controlled keys. Because the consuming set() function then enumerates the merged object with another for...in, every key the attacker placed on the polluted prototype lands in the resulting Set-Cookie string as an attribute pair. The attacker can set domain=, secure=, samesite=, expires=, and path= on cookies whose attributes the developer thought were locked down. This issue has been patched in version 3.0.7.
Lifecycle
Complete event history — 7 events, chronological
| Date | Event | Detail |
| May 15, 2026 | Reserved | Reserved by GitHub_M |
| June 10, 2026 | Published | Published (CNA: GitHub_M) |
| August 26, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-46625 (js-cookie). Public exploit reference added. |
| August 28, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-46625 (js-cookie). Public exploit reference added. |
| September 4, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-46625 (js-cookie). Public exploit reference added. |
| September 7, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-46625 (js-cookie). Public exploit reference added. |
| September 9, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-46625 (js-cookie). Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| js-cookie | js-cookie | — | < 3.0.7 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-46625 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.