Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x27p-fpr7-4wpm

Опубликовано: 18 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.5

Описание

Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like proto, combined with jQuery's unsafe element creation that traversed the prototype chain.

Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like proto, combined with jQuery's unsafe element creation that traversed the prototype chain.

8.5 High

CVSS4

Дефекты

CWE-1321

8.5 High

CVSS4

Дефекты

CWE-1321