CVE-2023-26139
Last modified
CVE-2023-26139 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Versions of the package underscore-keypath from 0.0.11 are vulnerable to Prototype Pollution via the name argument of the setProperty() function. Exploiting this vulnerability is possible due to improper input sanitization which allows the usage of arguments like “__proto__”.. EPSS estimates a 0.74% chance of exploitation in the next 30 days.
Description
Versions of the package underscore-keypath from 0.0.11 are vulnerable to Prototype Pollution via the name argument of the setProperty() function. Exploiting this vulnerability is possible due to improper input sanitization which allows the usage of arguments like “__proto__”.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Underscore-Keypath Project | Underscore-Keypath | >= 0.0.11 |
References
- https://gist.github.com/lelecolacola123/cc0d1e73780127aea9482c05f2ff3252Third Party Advisory
- https://security.snyk.io/vuln/SNYK-JS-UNDERSCOREKEYPATH-5416714Third Party Advisory
- https://gist.github.com/lelecolacola123/cc0d1e73780127aea9482c05f2ff3252Third Party Advisory
- https://security.snyk.io/vuln/SNYK-JS-UNDERSCOREKEYPATH-5416714Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-26139?
How severe is CVE-2023-26139?
How do I fix CVE-2023-26139?
Are you affected by CVE-2023-26139?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
