CVE-2022-37266

CRITICAL

stealjs steal - Prototype Pollution via babel.js extend Function

Title source: llm
STIX 2.1

Description

Prototype pollution vulnerability in function extend in babel.js in stealjs steal 2.2.4 via the key variable in babel.js.

Scores

CVSS v3 9.8
EPSS 0.0101
EPSS Percentile 58.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-1321
Status published
Products (2)
npm/steal 0npm
stealjs/steal 2.2.4
Published Sep 15, 2022
Tracked Since Feb 18, 2026