Skip to main content
QUIETLYTIC
Vulnerability

browserslist Prototype Pollution (CVE-2026-73088)

CVE-2026-73088 lets an untrusted browserslist-stats.json file crash or pollute the prototype of any Node.js process calling Browserslist, fixed in 4.28.7.

CVE-2026-73088
Threat Level
HIGH
CVSS
7.5
Status
Monitored
Confidence
High
Affected Products
npm:browserslist

CVE-2026-73088 is a high-severity (CVSS 3.1 base 7.5) vulnerability in Browserslist, the npm package that determines target browser versions for Autoprefixer, Babel preset-env, Stylelint, and PostCSS — meaning this bug’s reach extends well beyond projects that depend on Browserslist directly.

What the vulnerability does

Browserslist auto-discovers a browserslist-stats.json file by walking up the directory tree from the project root on every call, regardless of the query being run, and passes its contents into an internal normalizeStats() function without validating the object’s keys. Per the GitHub Security Advisory (GHSA-73wf-gq98-2v4g), an attacker who can place such a file anywhere in that directory tree — via a pull request, a compromised dependency, or a build artifact — can trigger two distinct failures from the same root cause (an unguarded loop over untrusted object keys):

  1. Crash: a stats key matching a built-in Object.prototype member name (toString, valueOf, constructor, etc.) resolves to that inherited function instead of undefined, and the code then dereferences a property on it that doesn’t exist — an uncaught TypeError that crashes the process.
  2. Prototype pollution: a stats key of exactly __proto__ triggers the real Object.prototype.__proto__ setter on assignment, altering the internal object’s prototype chain rather than setting a plain property.

Because the vulnerable code path runs unconditionally on every Browserslist call, a single poisoned file breaks every subsequent call in that project — including calls made internally by build tooling for entirely unrelated queries.

Fix and affected versions

Fixed in Browserslist 4.28.7, per the GitHub Advisory. The fix replaces the plain-object accumulator with a null-prototype object and adds an explicit hasOwnProperty check, so a stats key can no longer resolve to an inherited prototype member or mutate the object’s own prototype chain.

Why this matters

No authentication is required — only the ability to add a file to a project’s directory tree (an external contributor’s PR, a compromised transitive dependency) or influence the stats option programmatically. Given Browserslist’s position as a transitive dependency of extremely widely used build tools, a CI pipeline that runs any Browserslist-dependent step (Autoprefixer, Babel, Stylelint, PostCSS) on untrusted contributions is the realistic exposure path, not direct end-user usage.

Frequently Asked Questions

What is CVE-2026-73088? A high-severity (CVSS 7.5) vulnerability in the Browserslist npm package where an untrusted browserslist-stats.json file can crash the process or pollute an internal object’s prototype.

Which version fixes CVE-2026-73088? Browserslist 4.28.7 and later.

Is CVE-2026-73088 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.


Data sourced from the GitHub Advisory Database and the National Vulnerability Database (NVD), aggregated September 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 GitHub Advisory Database
02 National Vulnerability Database (NVD)

Related intelligence


Analyst tools