← back
CVE-2021-25914criticalCWE-1321

CVE-2021-25914

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8epss 3.7%
exploitation probability
3.7%top 11% of all CVEs
observed exploitation
nono source reports it
In short

A flaw in the 'object-collider' library allows attackers to pollute JavaScript object prototypes, potentially crashing applications or executing malicious code remotely.

Technical detail

Prototype pollution vulnerability in 'object-collider' versions 1.0.0–1.0.3 enables an attacker to inject properties into Object.prototype through crafted input, causing denial of service via application crash or potentially achieving remote code execution depending on the application's object handling and execution context.

Summary generated and translated by AI from the official description.
Prototype pollution vulnerability in 'object-collider' versions 1.0.0 through 1.0.3 allows attacker to cause a denial of service and may lead to remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · object-collider