← back
CVE-2021-25943criticalCWE-1321

CVE-2021-25943

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8epss 3.3%
exploitation probability
3.3%top 13% of all CVEs
observed exploitation
nono source reports it
In short

A flaw in the '101' library allows attackers to pollute object prototypes, which can crash the application or potentially execute malicious code remotely.

Technical detail

Prototype pollution vulnerability in '101' versions 1.0.0–1.6.3 enables attackers to modify the prototype chain of JavaScript objects through untrusted input, leading to denial of service or remote code execution depending on application context and gadget availability.

Summary generated and translated by AI from the official description.
Prototype pollution vulnerability in '101' versions 1.0.0 through 1.6.3 allows an attacker to cause a denial of service and may lead to remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · 101