← back
CVE-2021-25928criticalCWE-1321

CVE-2021-25928

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8epss 3.3%
exploitation probability
3.3%top 13% of all CVEs
observed exploitation
nono source reports it
In short

A flaw in the 'safe-obj' library allows attackers to inject malicious properties into JavaScript objects through specially crafted input, potentially crashing the application or executing unauthorized code.

Technical detail

Prototype pollution vulnerability in 'safe-obj' (v1.0.0–1.0.2) enables an attacker to pollute the Object prototype via untrusted input, leading to denial of service through application crash and potential remote code execution depending on downstream usage of affected objects.

Summary generated and translated by AI from the official description.
Prototype pollution vulnerability in 'safe-obj' versions 1.0.0 through 1.0.2 allows an attacker to cause a denial of service and may lead to remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · safe-obj