CVE-2019-20149
HIGHKind-of < 6.0.3 - Exposure to Wrong Actor
Title source: ruleDescription
ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflicting name, as demonstrated by 'constructor': {'name':'Symbol'}. Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection result.
Exploits (1)
Scores
CVSS v3
7.5
EPSS
0.0018
EPSS Percentile
40.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Classification
CWE
CWE-668
Status
published
Affected Products (2)
kind-of_project/kind-of
npm/kind-of
< 6.0.3npm
Timeline
Published
Dec 30, 2019
Tracked Since
Feb 18, 2026