{"id":"CVE-2024-38983","details":"Prototype Pollution in alykoshin mini-deep-assign v0.0.8 allows an attacker to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via the _assign() method at (/lib/index.js:91)","modified":"2026-08-12T03:51:41.092576691Z","published":"2024-07-30T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/38xxx/CVE-2024-38983.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://gist.github.com/mestrtee/f82d0c3a8fe3a125f06425caef5d22ed"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/38xxx/CVE-2024-38983.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-38983"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/alykoshin/mini-deep-assign","events":[{"introduced":"e0758103c4c29b20cbad0caca7bd40853437879e"},{"last_affected":"e0758103c4c29b20cbad0caca7bd40853437879e"}],"database_specific":{"cpe":"cpe:2.3:a:alykoshin:mini-deep-assign:0.0.8:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.0.8"},{"last_affected":"0.0.8"}],"source":"CPE_STRING"}}],"versions":["0.0.8","v0.0.8"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-38983.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}