CVE-2022-25296
MEDIUMbodymen < 1.1.1 - Prototype Pollution via Handler Function
Title source: llmDescription
The package bodymen from 0.0.0 are vulnerable to Prototype Pollution via the handler function which could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload. **Note:** This vulnerability derives from an incomplete fix to [CVE-2019-10792](https://security.snyk.io/vuln/SNYK-JS-BODYMEN-548897)
References (1)
Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-JS-BODYMEN-2342623
Scores
CVSS v3
6.3
EPSS
0.0027
EPSS Percentile
50.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Details
CWE
CWE-1321
Status
published
Products (2)
bodymen_project/bodymen
< 1.1.1
npm/bodymen
0.0.0npm
Published
Mar 17, 2022
Tracked Since
Feb 18, 2026