CVE-2026-102600: Socket.IO: Prototype Pollution via Unsafe Client Session Lookup
### Impact This is a **prototype pollution / improper client lookup** vulnerability in `@socket.io/cluster-engine`. Servers using `@socket.io/cluster-engine` may be impacted when attacker-controlled session IDs are processed in clustered deployments. A malicious client could use special property names such as `__proto__`, `constructor`, or other inherited object keys as a session identifier, causing the server to read properties from the object prototype chain instead of only real connected clients. The impact is **denial of service** through process crash. Applications not using `@socket.io/cluster-engine` are not affected by this specific issue. Affected versions: * `@socket.io/[email protected]` ### Patches The issue was fixed in: * `@socket.io/[email protected]` ### Workarounds If upgrading immediately is not possible, users can reduce exposure by: - Rejecting or sanitizing suspicious session IDs before they reach the cluster engine. - Running the cluster engine behind trusted infrastructure that prevents arbitrary clients from crafting raw Engine.IO session-related requests. These workarounds are defense-in-depth only. Upgrading to a patched version is recommended.
Recommended action
Recommended action
Upgrade affected packages to a patched version: @socket.io/cluster-engine 0.1.1.
Technical details
- Vendor
- Not specified
- Product
- @socket.io/cluster-engine
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source