CVE-2024-21548

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
18/12/2024
Last modified:
24/07/2025

Description

Versions of the package bun after 0.0.12 and before 1.1.30 are vulnerable to Prototype Pollution due to improper input sanitization. An attacker can exploit this vulnerability through Bun&amp;#39;s APIs that accept objects.<br /> <br /> **Note:** This issue relates to the widely known and actively developed &amp;#39;Bun&amp;#39; JavaScript runtime. The bun package on NPM at versions 0.0.12 and below belongs to a different and older project that happened to claim the &amp;#39;bun&amp;#39; name in the past.