CVE-2024-21548
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
18/12/2024
Last modified:
24/07/2025
Description
Versions of the package bun after 0.0.12 and before 1.1.30 are vulnerable to Prototype Pollution due to improper input sanitization. An attacker can exploit this vulnerability through Bun&#39;s APIs that accept objects.<br />
<br />
**Note:** This issue relates to the widely known and actively developed &#39;Bun&#39; JavaScript runtime. The bun package on NPM at versions 0.0.12 and below belongs to a different and older project that happened to claim the &#39;bun&#39; name in the past.
Impact
Base Score 4.0
7.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH



