Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3c3p-xh4f-pfh7

Опубликовано: 24 сент. 2025
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

json-schema-editor-visual vulnerable to prototype pollution

json-schema-editor-visual is a package that provides jsonschema editor. A Prototype Pollution vulnerability in the setData and deleteData function of json-schema-editor-visual versions thru 1.1.1 allows attackers to inject or delete properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.

Пакеты

Наименование

json-schema-editor-visual

npm
Затронутые версииВерсия исправления

<= 2.0.0

Отсутствует

EPSS

Процентиль: 18%
0.00057
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-1321

Связанные уязвимости

CVSS3: 6.5
nvd
5 месяцев назад

json-schema-editor-visual is a package that provides jsonschema editor. A Prototype Pollution vulnerability in the setData and deleteData function of json-schema-editor-visual versions thru 1.1.1 allows attackers to inject or delete properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.

EPSS

Процентиль: 18%
0.00057
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-1321