CVE-2024-29650
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/03/2024
Last modified:
15/04/2026
Description
An issue in @thi.ng/paths v.5.1.62 and before allows a remote attacker to execute arbitrary code via the mutIn and mutInManyUnsafe components.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
References to Advisories, Solutions, and Tools
- https://gist.github.com/tariqhawis/1bc340ca5ea6ae115c9ab9665cfd5921
- https://learn.snyk.io/lesson/prototype-pollution/#a0a863a5-fd3a-539f-e1ed-a0769f6c6e3b
- https://gist.github.com/tariqhawis/1bc340ca5ea6ae115c9ab9665cfd5921
- https://learn.snyk.io/lesson/prototype-pollution/#a0a863a5-fd3a-539f-e1ed-a0769f6c6e3b
- https://www.vicarius.io/vsociety/posts/unwinding-cve-2024-29650-a-tale-of-javascript-source-code-review-to-unravel-the-mysterious-prototype-pollution-amid-of-loose-defenses



