The maintainers of Style Dictionary patched a prototype pollution vulnerability in the convertTokenData() utility, tracked as GHSA-vj5c-m527-mpff, after finding that malicious token keys containing __proto__ could modify Object.prototype during conversion back into object form. The flaw affects versions 4.3.0 through 5.4.3 and can be reached through direct calls to convertTokenData(), indirectly via the Expand API, or during the project’s transform lifecycle when token data is synchronized into objects.
The fix was merged in commit 23b5e8d through pull request #1702 after linked security issue #1699 was resolved, and it adds a guard that ignores tokens whose keys include __proto__, along with a test confirming that payloads such as {__proto__.a} no longer pollute global object properties. The advisory says impact is greatest when Style Dictionary is embedded in Node.js server applications, moderate in web applications, and lower where token input is tightly controlled; users should upgrade to version 5.4.4, or recursively sanitize token data for __proto__ keys as a workaround.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A GitHub security advisory disclosed a prototype pollution vulnerability in style-dictionary affecting versions 4.3.0 through 5.4.3. The advisory said the issue was fixed in version 5.4.4 and recommended sanitizing token data for __proto__ keys as a workaround on vulnerable versions.
A pull request to fix prototype pollution in style-dictionary's convertTokenData() utility was merged into the main branch after passing checks. The patch added a guard to ignore token keys containing __proto__ and included a test to verify Object.prototype is not polluted.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.