CVE-2026-73088 is a high-severity (CVSS 3.1 base 7.5) vulnerability in Browserslist, the npm package that determines target browser versions for Autoprefixer, Babel preset-env, Stylelint, and PostCSS — meaning this bug’s reach extends well beyond projects that depend on Browserslist directly.
What the vulnerability does
Browserslist auto-discovers a browserslist-stats.json file by walking up the directory tree from the project root on every call, regardless of the query being run, and passes its contents into an internal normalizeStats() function without validating the object’s keys. Per the GitHub Security Advisory (GHSA-73wf-gq98-2v4g), an attacker who can place such a file anywhere in that directory tree — via a pull request, a compromised dependency, or a build artifact — can trigger two distinct failures from the same root cause (an unguarded loop over untrusted object keys):
- Crash: a stats key matching a built-in
Object.prototypemember name (toString,valueOf,constructor, etc.) resolves to that inherited function instead ofundefined, and the code then dereferences a property on it that doesn’t exist — an uncaughtTypeErrorthat crashes the process. - Prototype pollution: a stats key of exactly
__proto__triggers the realObject.prototype.__proto__setter on assignment, altering the internal object’s prototype chain rather than setting a plain property.
Because the vulnerable code path runs unconditionally on every Browserslist call, a single poisoned file breaks every subsequent call in that project — including calls made internally by build tooling for entirely unrelated queries.
Fix and affected versions
Fixed in Browserslist 4.28.7, per the GitHub Advisory. The fix replaces the plain-object accumulator with a null-prototype object and adds an explicit hasOwnProperty check, so a stats key can no longer resolve to an inherited prototype member or mutate the object’s own prototype chain.
Why this matters
No authentication is required — only the ability to add a file to a project’s directory tree (an external contributor’s PR, a compromised transitive dependency) or influence the stats option programmatically. Given Browserslist’s position as a transitive dependency of extremely widely used build tools, a CI pipeline that runs any Browserslist-dependent step (Autoprefixer, Babel, Stylelint, PostCSS) on untrusted contributions is the realistic exposure path, not direct end-user usage.
Frequently Asked Questions
What is CVE-2026-73088?
A high-severity (CVSS 7.5) vulnerability in the Browserslist npm package where an untrusted browserslist-stats.json file can crash the process or pollute an internal object’s prototype.
Which version fixes CVE-2026-73088? Browserslist 4.28.7 and later.
Is CVE-2026-73088 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.
Data sourced from the GitHub Advisory Database and the National Vulnerability Database (NVD), aggregated September 2026. See more vulnerability intelligence.