{"id":"GHSA-8v3j-jfg3-v3fv","summary":"Prototype Pollution in Sails.js","details":"Sails.js \u003c= 1.5.2 is vulnerable to Prototype Pollution via controller/load-action-modules.js, function loadActionModules(). A [patch](https://github.com/balderdashy/sails/commit/7c5379a656bb305c958df1dcc2b51a9668830358) is available in the `master` branch of Sails.js's GItHub repository.","aliases":["CVE-2021-44908"],"modified":"2023-11-08T04:07:19.089457Z","published":"2022-03-18T00:01:11Z","database_specific":{"github_reviewed_at":"2022-03-18T23:04:49Z","nvd_published_at":"2022-03-17T12:15:00Z","cwe_ids":["CWE-1321"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-44908"},{"type":"WEB","url":"https://github.com/balderdashy/sails/issues/7209"},{"type":"WEB","url":"https://github.com/balderdashy/sails/commit/7c5379a656bb305c958df1dcc2b51a9668830358"},{"type":"WEB","url":"https://github.com/Marynk/JavaScript-vulnerability-detection/blob/main/sailsJS%20PoC.zip"},{"type":"PACKAGE","url":"https://github.com/balderdashy/sails"},{"type":"WEB","url":"https://github.com/balderdashy/sails/blob/master/lib/app/private/controller/load-action-modules.js#L32"}],"affected":[{"package":{"name":"sails","ecosystem":"npm","purl":"pkg:npm/sails"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.5.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-8v3j-jfg3-v3fv/GHSA-8v3j-jfg3-v3fv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}