{"id":"CVE-2021-41097","details":"aurelia-path is part of the Aurelia platform and contains utilities for path manipulation. There is a prototype pollution vulnerability in aurelia-path before version 1.1.7. The vulnerability exposes Aurelia application that uses `aurelia-path` package to parse a string. The majority of this will be Aurelia applications that employ the `aurelia-router` package. An example is this could allow an attacker to change the prototype of base object class `Object` by tricking an application to parse the following URL: `https://aurelia.io/blog/?__proto__[asdf]=asdf`. The problem is patched in version `1.1.7`.","aliases":["GHSA-3c9c-2p65-qvwv"],"modified":"2026-07-09T12:20:19.990436Z","published":"2021-09-27T18:15:08.443Z","references":[{"type":"ADVISORY","url":"https://github.com/aurelia/path/releases/tag/1.1.7"},{"type":"ADVISORY","url":"https://github.com/aurelia/path/security/advisories/GHSA-3c9c-2p65-qvwv"},{"type":"ADVISORY","url":"https://www.npmjs.com/package/aurelia-path"},{"type":"REPORT","url":"https://github.com/aurelia/path/issues/44"},{"type":"FIX","url":"https://github.com/aurelia/path/commit/7c4e235433a4a2df9acc313fbe891758084fdec1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/aurelia/path","events":[{"introduced":"0"},{"fixed":"3c674eff2ba3856f0f132503fec78597666b2b7e"},{"fixed":"7c4e235433a4a2df9acc313fbe891758084fdec1"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.1.7"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:bluespire:aurelia-path:*:*:*:*:*:node.js:*:*"}}],"versions":["1.1.5","1.1.4","1.1.3","1.1.2","1.1.1","1.1.0","1.0.0","1.0.0-rc.1.0.0","1.0.0-beta.2.0.1","1.0.0-beta.2.0.0","1.0.0-beta.1.2.2","1.0.0-beta.1.2.1","1.0.0-beta.1.2.0","1.0.0-beta.1.1.1","1.0.0-beta.1.1.0","1.0.0-beta.1","0.11.0","0.10.0","0.9.0","0.8.1","0.8.0","0.7.0","0.6.1","0.6.0","0.5.0","0.4.6","0.4.5","0.4.4","0.4.3","0.4.2","0.4.1","0.4.0","0.3.0","0.2.2","0.2.1","0.2.0","0.1.0","0.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-41097.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}