Glossary
Prototype pollution
Untrusted data writing to __proto__ and changing every object.
In JavaScript, assigning to an object key named __proto__ can alter the prototype every other object inherits from. If a parser copies untrusted keys into an object without checking, a document containing __proto__ can change application-wide behaviour, adding properties that appear on objects that never had them, or overriding methods.
The usual path is a deep merge or a key-by-key copy over parsed JSON or YAML. The data looks ordinary, the parse succeeds, and the damage happens during the copy rather than the parse.
Defences are straightforward: reject or skip the keys __proto__, constructor and prototype when building objects from untrusted input, and use a null-prototype object or a Map where arbitrary keys are expected.