CVE-2021-25915
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.8epss 3.5%
exploitation probability
3.5%top 11% of all CVEs
observed exploitation
nono source reports it
In short
A flaw in the 'changeset' library allows attackers to pollute JavaScript object prototypes, potentially crashing the application or executing malicious code. This happens because the library improperly handles object properties during version 0.0.1 to 0.2.5.
Technical detail
Prototype pollution vulnerability in changeset (versions 0.0.1–0.2.5) enables attackers to inject properties into Object.prototype through unsanitized input, resulting in denial of service via application crash or potentially remote code execution depending on downstream usage of polluted objects.
Summary generated and translated by AI from the official description.
Prototype pollution vulnerability in 'changeset' versions 0.0.1 through 0.2.5 allows an attacker to cause a denial of service and may lead to remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · changeset