{"id":"CVE-2021-3815","details":"utils.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')","aliases":["GHSA-3xph-cp8f-2229"],"modified":"2026-07-08T22:14:50.770790Z","published":"2021-12-08T17:15:10.927Z","references":[{"type":"FIX","url":"https://github.com/fabiocaccamo/utils.js/commit/102efafb291ce1916985514440d3bf8a6826890a"},{"type":"FIX","url":"https://huntr.dev/bounties/20f48c63-f078-4173-bcac-a9f34885f2c0"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/fabiocaccamo/utils.js","events":[{"introduced":"0"},{"fixed":"d9ebbcdbcd7b89abeeb240952ff5ab01ca372a5f"},{"fixed":"102efafb291ce1916985514440d3bf8a6826890a"}],"database_specific":{"cpe":"cpe:2.3:a:utils.js_project:utils.js:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.17.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["0.17.1","0.17.0","0.16.0","0.15.0","0.14.2","0.14.1","0.14.0","0.13.0","0.12.0","0.11.0","0.10.0","0.9.15","0.9.14","0.9.13","0.9.12","0.9.11","0.9.10","0.9.9","0.9.8","0.9.7","0.9.6","0.9.5","0.9.4","0.9.3","0.9.2","0.9.1","0.9.0","0.8.2","0.8.1","0.8.0","0.7.0","0.6.0","0.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3815.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}