Advisories for Npm/@Socket.io/Cluster-Engine package

2026

Socket.IO: Prototype Pollution via Unsafe Client Session Lookup

This is a prototype pollution / improper client lookup vulnerability in @socket.io/cluster-engine. Servers using @socket.io/cluster-engine may be impacted when attacker-controlled session IDs are processed in clustered deployments. A malicious client could use special property names such as proto, constructor, or other inherited object keys as a session identifier, causing the server to read properties from the object prototype chain instead of only real connected clients. The impact is denial of …