6.5 Medium
AI Score
Confidence
Low
0.002 Low
EPSS
Percentile
59.1%
The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.
github.com/digitalbazaar/forge/blob/master/CHANGELOG.md
snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-609293
snyk.io/vuln/SNYK-JS-NODEFORGE-598677