-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| @cat5th/key-serializer | npm | <= 0.2.5 |
The advisory's PoC demonstrates exploitation through query, set, default.query, and default.set functions using proto payloads. All four entry points show the same pattern of unsafely handling property assignments without prototype protection. The vulnerability stems from improper input sanitization in these key manipulation functions, allowing attackers to modify Object.prototype properties.
Ongoing coverage of React2Shell