{"id":"CVE-2021-23438","details":"This affects the package mpath before 0.8.4. A type confusion vulnerability can lead to a bypass of CVE-2018-16490. In particular, the condition ignoreProperties.indexOf(parts[i]) !== -1 returns -1 if parts[i] is ['__proto__']. This is because the method that has been called if the input is an array is Array.prototype.indexOf() and not String.prototype.indexOf(). They behave differently depending on the type of the input.","aliases":["GHSA-p92x-r36w-9395"],"modified":"2026-07-09T05:13:45.176155Z","published":"2021-09-01T19:15:07.440Z","related":["SNYK-JAVA-ORGWEBJARSNPM-1579548","SNYK-JS-MPATH-1577289"],"references":[{"type":"FIX","url":"https://github.com/aheckmann/mpath/commit/89402d2880d4ea3518480a8c9847c541f2d824fc"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1579548"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JS-MPATH-1577289"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mongoosejs/mpath","events":[{"introduced":"0"},{"fixed":"634a0fa0f97bf1d00791647e3094273ba360a9ed"},{"fixed":"89402d2880d4ea3518480a8c9847c541f2d824fc"}],"database_specific":{"cpe":"cpe:2.3:a:mpath_project:mpath:*:*:*:*:*:node.js:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.8.4"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["0.8.3","0.8.2","0.8.1","0.8.0","0.7.0","0.6.0","0.5.2","0.5.1","0.5.0","0.4.1","0.3.0","0.2.1","0.2.0","0.1.1","0.1.0","0.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-23438.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}