cbcvebase.
CVE-2021-23518
published 2022-01-21

CVE-2021-23518: The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in…

PriorityP350critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.94%
78.1th percentile
The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the object is used to create the cached relative path. When using the origin path as __proto__, the attribute of the object is accessed instead of a path. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-CACHEDPATHRELATIVE-72573

Affected

5 ranges
VendorProductVersion rangeFixed in
cached-path-relative_projectcached-path-relative< 1.1.01.1.0
cached-path-relative_projectcached-path-relative>= 0 < 1.1.01.1.0
cached-path-relative_projectcached-path-relative>= unspecified < 1.1.01.1.0
debiandebian_linux
debiannode-cached-path-relative< node-cached-path-relative 1.1.0+~1.0.0-1 (bookworm)node-cached-path-relative 1.1.0+~1.0.0-1 (bookworm)

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.