GHSA-9mx2-prfp-8hqp
Dashboard / Vulnerabilities / GHSA-9mx2-prfp-8hqp
GHSA-9mx2-prfp-8hqp
Published: 10 May 2021Last Modified: 8 Jul 2026
Summary: Prototype Pollution in simpl-schema
Details: This affects the package simpl-schema before 1.10.2. Attacker controlled input into a schema could result in remote code execution within the scope of the surrounding application.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-7742, https://github.com/longshotlabs/simpl-schema/commit/50128841fa7fc2d137c36a397054279144caea3d, https://github.com/longshotlabs/simpl-schema/releases/tag/1.10.2, https://snyk.io/vuln/SNYK-JS-SIMPLSCHEMA-1016157
Affected packages
Package
Name: simpl-schema
Purl: pkg:npm/simpl-schema
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -1.10.2
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
