CVE-2026-24888 | Microsoft maker.js up to 0.19.1 hasOwnProperty prototype pollution (GHSA-2cp6-34r9-54xx / EUVD-2026-4851)
A vulnerability classified as critical was found in Microsoft maker.js up to 0.19.1. Affected by this issue is the function hasOwnProperty. Such manipulation leads to improperly controlled modification of object prototype attributes.
This vulnerability is uniquely identified as CVE-2026-24888. The attack can be launched remotely. No exploit exists.
A patch should be applied to remediate this issue.