CVE-2026-46625 | js-cookie JavaScript Cookie up to 3.0.6 assign prototype pollution (GHSA-qjx8-664m-686j / EUVD-2026-36154)
A vulnerability has been found in js-cookie JavaScript Cookie up to 3.0.6 and classified as problematic. This issue affects the function assign. Performing a manipulation results in improperly controlled modification of object prototype attributes.
This vulnerability is known as CVE-2026-46625. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.