{"id":"GHSA-gff7-g5r8-mg8m","summary":"Prototype Pollution in simple-plist","details":"simple-plist v1.3.0 was discovered to contain a prototype pollution vulnerability via .parse().","aliases":["CVE-2022-26260"],"modified":"2023-11-08T04:08:53.675072Z","published":"2022-03-23T00:00:22Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-03-29T13:08:19Z","nvd_published_at":"2022-03-22T19:15:00Z","cwe_ids":["CWE-1321"],"severity":"CRITICAL"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-26260"},{"type":"WEB","url":"https://github.com/wollardj/simple-plist/issues/60"},{"type":"WEB","url":"https://github.com/wollardj/simple-plist/issues/60#issuecomment-1083991840"},{"type":"WEB","url":"https://github.com/wollardj/simple-plist/commit/670e22fd6e46549a1d32d1065981e0f58eab98d6"},{"type":"PACKAGE","url":"https://github.com/wollardj/simple-plist"}],"affected":[{"package":{"name":"simple-plist","ecosystem":"npm","purl":"pkg:npm/simple-plist"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.3.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-gff7-g5r8-mg8m/GHSA-gff7-g5r8-mg8m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}