CVE-2022-37609
CRITICALjs-beautify 1.13.7 - Prototype Pollution via Name Variable in options.js
Title source: llmDescription
Prototype pollution vulnerability in beautify-web js-beautify 1.13.7 via the name variable in options.js.
References (3)
Core 3
Core References
Third Party Advisory
https://github.com/beautify-web/js-beautify/blob/6fa891e982cc3d615eed9a1a20a4fc50721bff16/js/src/core/options.js#L167
Third Party Advisory
https://github.com/beautify-web/js-beautify/blob/6fa891e982cc3d615eed9a1a20a4fc50721bff16/js/src/core/options.js#L167.aa
Issue Tracking, Third Party Advisory
https://github.com/beautify-web/js-beautify/issues/2106
Scores
CVSS v3
9.8
EPSS
0.0124
EPSS Percentile
65.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-1321
Status
published
Products (1)
js-beautify_project/js-beautify
1.13.7
Published
Oct 11, 2022
Tracked Since
Feb 18, 2026