Prototype Pollution Vulnerability in cli-util by npm Inc.
CVE-2024-57078

7.5HIGH

Key Information:

Vendor

npm Inc.

Status
Vendor
CVE Published:
5 February 2025

What is CVE-2024-57078?

A vulnerability in the lib.merge function of cli-util v1.1.27 allows attackers to exploit prototype pollution. By sending a specially crafted payload, an attacker can disrupt normal operations, leading to potential Denial of Service (DoS). This can have significant implications for applications relying on cli-util, making it essential for developers to apply necessary patches and safeguards to mitigate associated risks.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.