CVE-2022-41714

MEDIUM

fastest-json-copy <1.0.1 - Code Injection

Title source: llm
STIX 2.1

Description

fastest-json-copy version 1.0.1 allows an external attacker to edit or add new properties to an object. This is possible because the application does not correctly validate the incoming JSON keys, thus allowing the '__proto__' property to be edited.

Scores

CVSS v3 5.3
EPSS 0.0033
EPSS Percentile 55.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-1321
Status published
Products (2)
fastest-json-copy_project/fastest-json-copy 1.0.1
npm/fastest-json-copy 0npm
Published Nov 03, 2022
Tracked Since Feb 18, 2026