CVE-2026-45302 | milamer parse-nested-form-data up to 1.0.0 parseFormData names prototype pollution (GHSA-xp7r-j8r6-j9h3)
A vulnerability marked as critical has been reported in milamer parse-nested-form-data up to 1.0.0. This affects the function parseFormData. Performing a manipulation of the argument names results in improperly controlled modification of object prototype attributes.
This vulnerability is cataloged as CVE-2026-45302. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.