{"id":"GHSA-89qm-hm2x-mxm3","summary":"progressbar.js vulnerable to Prototype Pollution","details":"All versions of the package progressbar.js prior to 1.1.1 are vulnerable to Prototype Pollution via the function extend() in the file utils.js.\n\n","aliases":["CVE-2023-26133"],"modified":"2023-11-08T04:11:59.374308Z","published":"2023-06-12T06:30:17Z","database_specific":{"cwe_ids":["CWE-1321"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2023-06-12T18:53:32Z","nvd_published_at":"2023-06-12T05:15:09Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-26133"},{"type":"WEB","url":"https://github.com/kimmobrunfeldt/progressbar.js/commit/97fe68ef4beccfe84b7cba08ea1fc695e38cc04b"},{"type":"PACKAGE","url":"https://github.com/kimmobrunfeldt/progressbar.js"},{"type":"WEB","url":"https://github.com/kimmobrunfeldt/progressbar.js/blob/74536b9eeeaaf51144706d918ed5a0a679631d96/src/utils.js#L18"},{"type":"WEB","url":"https://github.com/kimmobrunfeldt/progressbar.js/blob/74536b9eeeaaf51144706d918ed5a0a679631d96/src/utils.js#L20"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-PROGRESSBARJS-3184152"}],"affected":[{"package":{"name":"progressbar.js","ecosystem":"npm","purl":"pkg:npm/progressbar.js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.1.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/06/GHSA-89qm-hm2x-mxm3/GHSA-89qm-hm2x-mxm3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"}]}