{"id":"GHSA-236c-vhj4-gfxg","summary":"Duplicate Advisory: Embedded malware in ua-parser-js","details":"### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-pjwm-rvh2-c87w. This link is maintained to preserve external references.\n\n### Original Description\nA vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This issue affects the crypto mining component which introduces a backdoor. Upgrading to version 0.7.30, 0.8.1 and 1.0.1 is able to address this issue. It is recommended to upgrade the affected component.","modified":"2026-02-22T22:59:47.461948Z","published":"2022-05-25T00:00:31Z","withdrawn":"2026-02-17T21:40:20Z","database_specific":{"github_reviewed_at":"2026-02-17T21:40:20Z","nvd_published_at":"2022-05-24T16:15:00Z","cwe_ids":["CWE-829","CWE-912"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-4229"},{"type":"WEB","url":"https://github.com/faisalman/ua-parser-js/issues/536"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pjwm-rvh2-c87w"},{"type":"WEB","url":"https://vuldb.com/?id.185453"}],"affected":[{"package":{"name":"ua-parser-js","ecosystem":"npm","purl":"pkg:npm/ua-parser-js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.7.29"},{"fixed":"0.7.30"}]}],"versions":["0.7.29"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-236c-vhj4-gfxg/GHSA-236c-vhj4-gfxg.json"}},{"package":{"name":"ua-parser-js","ecosystem":"npm","purl":"pkg:npm/ua-parser-js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.8.0"},{"fixed":"0.8.1"}]}],"versions":["0.8.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-236c-vhj4-gfxg/GHSA-236c-vhj4-gfxg.json"}},{"package":{"name":"ua-parser-js","ecosystem":"npm","purl":"pkg:npm/ua-parser-js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.0.0"},{"fixed":"1.0.1"}]}],"versions":["1.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-236c-vhj4-gfxg/GHSA-236c-vhj4-gfxg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}