9.8
CVSSv3

CVE-2022-37598

Published: 20/10/2022 Updated: 17/05/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Prototype pollution vulnerability in function DEFNODE in ast.js in mishoo UglifyJS 3.13.2 via the name variable in ast.js. NOTE: the vendor considers this an invalid report.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

uglifyjs project uglifyjs 3.13.2

Vendor Advisories

DescriptionThe MITRE CVE dictionary describes this issue as: Prototype pollution vulnerability in function DEFNODE in astjs in mishoo UglifyJS 3132 via the name variable in astjs ...