CVE-2015-8857

CRITICAL9.8EPSS 0.27%

Incorrect Handling of Non-Boolean Comparisons During Minification in uglify-js

Published: 10/24/2017Modified: 4/28/2026

Description

The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expressions, which might allow attackers to bypass security mechanisms or possibly have unspecified other impact by leveraging improperly rewritten Javascript.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (9)