CVE-2021-3918
Critical
CVE-2021-3918
json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Exploit probability
3.6%
Published
November 13, 2021
Required by
Not available
Last source change
July 8, 2026
02 / AFFECTED SOFTWARE
Affected packages
6 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2021-3918
View original source
json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Open Source Vulnerabilities
GHSA-896r-f27r-55mw
View original source
json-schema before version 0.4.0 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution').
05 / REFERENCES
Further evidence
- https://github.com/kriszyp/json-schema/commit/22f146111f541d9737e832823699ad3528ca7741
- https://huntr.dev/bounties/bb6ccd63-f505-4e3a-b55f-cd2662c261a9
- https://lists.debian.org/debian-lts-announce/2022/12/msg00013.html
- https://security.netapp.com/advisory/ntap-20250117-0004/
- https://github.com/kriszyp/json-schema
- https://github.com/kriszyp/json-schema/commit/b62f1da1ff5442f23443d6be6a92d00e65cba93a
- https://github.com/kriszyp/json-schema/commit/f6f6a3b02d667aa4ba2d5d50cc19208c4462abfa
- https://nvd.nist.gov/vuln/detail/CVE-2021-3918
- https://security.netapp.com/advisory/ntap-20250117-0004