CVE-2022-21211

MEDIUM

posix - Denial of Service via toString Method Invocation

Title source: llm
STIX 2.1

Description

This affects all versions of package posix. When invoking the toString method, it will fallback to 0x0 value, as the value of toString is not invokable (not a function), and then it will crash with type-check.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-JS-POSIX-2400719

Scores

CVSS v3 5.9
EPSS 0.0094
EPSS Percentile 56.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-252
Status published
Products (2)
npm/posix 0npm
posix_project/posix
Published Jun 10, 2022
Tracked Since Feb 18, 2026