CVEs (3)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Object Path Project2Debian Linux Object PathJun 17, 2026 Sep 17, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
2Debian Object Path Project2Debian Linux Object PathJun 17, 2026 Aug 27, 2021 N/A· v4 8.6 HIGH· v3 7.5 HIGH· v2 This affects the package object-path before 0.11.6. A type confusion vulnerability can lead to a bypass of CVE-2020-15256 when the path components used in the path parameter are arrays. In particular, the condition curre...Show more |
1Object Path Project 1Object Path Jun 17, 2026 Oct 19, 2020 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 A prototype pollution vulnerability has been found in `object-path` <= 0.11.4 affecting the `set()` method. The vulnerability is limited to the `includeInheritedProps` mode (if version >= 0.11.0 is used), which has to be...Show more |