CVE-2022-25296

MEDIUM

bodymen < 1.1.1 - Prototype Pollution via Handler Function

Title source: llm
STIX 2.1

Description

The package bodymen from 0.0.0 are vulnerable to Prototype Pollution via the handler function which could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload. **Note:** This vulnerability derives from an incomplete fix to [CVE-2019-10792](https://security.snyk.io/vuln/SNYK-JS-BODYMEN-548897)

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-JS-BODYMEN-2342623

Scores

CVSS v3 6.3
EPSS 0.0027
EPSS Percentile 50.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-1321
Status published
Products (2)
bodymen_project/bodymen < 1.1.1
npm/bodymen 0.0.0npm
Published Mar 17, 2022
Tracked Since Feb 18, 2026