Unsanitized property assignment during streamed JSON parsing allows a remote attacker to mutate Object.prototype, leading to RCE in Express middleware contexts.
# Reproduction steps redacted under coordinated disclosure. # Full PoC will be published with the advisory at embargo expiry. $ zds reproduce ZDS-2025-0142