CVE-2021-44906

CRITICAL9.8EPSS 0.79%

Prototype Pollution in minimist

Published: 3/18/2022Modified: 3/13/2026
Also known as:GHSA-xvch-5gv4-984h

Description

Minimist prior to 1.2.6 and 0.2.4 is vulnerable to Prototype Pollution via file `index.js`, function `setKey()` (lines 69-95).

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (16)