OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-102600: Socket.IO: Prototype Pollution via Unsafe Client Session Lookup

GitHub Advisories · officialPublished Oct 5, 2026Risk 37/100

### Impact This is a **prototype pollution / improper client lookup** vulnerability in `@socket.io/cluster-engine`. Servers using `@socket.io/cluster-engine` may be impacted when attacker-controlled session IDs are processed in clustered deployments. A malicious client could use special property names such as `__proto__`, `constructor`, or other inherited object keys as a session identifier, causing the server to read properties from the object prototype chain instead of only real connected clients. The impact is **denial of service** through process crash. Applications not using `@socket.io/cluster-engine` are not affected by this specific issue. Affected versions: * `@socket.io/[email protected]` ### Patches The issue was fixed in: * `@socket.io/[email protected]` ### Workarounds If upgrading immediately is not possible, users can reduce exposure by: - Rejecting or sanitizing suspicious session IDs before they reach the cluster engine. - Running the cluster engine behind trusted infrastructure that prevents arbitrary clients from crafting raw Engine.IO session-related requests. These workarounds are defense-in-depth only. Upgrading to a patched version is recommended.

Upgrade affected packages to a patched version: @socket.io/cluster-engine 0.1.1.

Vendor
Not specified
Product
@socket.io/cluster-engine
Exploitation
none known
Evidence
official
CVSS
7.5

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source