# GHSA-x9vf-53q3-cvx6: CASL Ability is Vulnerable to Prototype Pollution

**Severity:** CRITICAL | **CVSS:** 9.8 | **Source:** ghsa

## Description

CASL Ability, versions 2.4.0 through 6.7.4, contains a prototype pollution vulnerability.

## CVSS

- **Score:** 9.8
- **Vector:** `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`

## Weakness

- [CWE-1321](https://cwe.mitre.org/data/definitions/1321.html)

## Affected Packages

### @casl/ability (npm)
- **Vulnerable:** `>= 2.4.0, <= 6.7.4`
- **Fixed in:** `6.7.5`

## References

**Commits:**
- https://github.com/stalniy/casl/commit/39da920ec1dfadf3655e28bd0389e960ac6871f4

**Advisories:**
- https://github.com/advisories/GHSA-x9vf-53q3-cvx6

**Other:**
- https://nvd.nist.gov/vuln/detail/CVE-2026-1774
- https://cwe.mitre.org/data/definitions/1321.html
- https://developer.mozilla.org/en-US/docs/Web/Security/Attacks/Prototype_pollution
- https://github.com/stalniy/casl/tree/master/packages/casl-ability
- https://www.kb.cert.org/vuls/id/458422
- https://github.com/stalniy/casl/pull/1093

## Related Identifiers

- CVE-2026-1774

---

**Source:** https://github.com/advisories/GHSA-x9vf-53q3-cvx6
**Published:** 2026-02-10
**Ingested:** 2026-02-19 19:30:23 UTC

## Reproduction Steps

_To be determined by the reproduction agent._
