Vulnerability Description
Versions of the package collection.js before 6.8.1 are vulnerable to Prototype Pollution via the extend function in Collection.js/dist/node/iterators/extend.js.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Collection.Js Project | Collection.Js | < 6.8.1 |
Related Weaknesses (CWE)
References
- https://github.com/kobezzza/Collection/blob/be32c48e68f49d3be48a58e929d1ab8ff1d2Broken Link
- https://github.com/kobezzza/Collection/commit/d3d937645f62f37d3115d6aa90bb510fd8Patch
- https://github.com/kobezzza/Collection/issues/27ExploitIssue TrackingPatch
- https://github.com/kobezzza/Collection/releases/tag/v6.8.1PatchRelease Notes
- https://security.snyk.io/vuln/SNYK-JS-COLLECTIONJS-3185148ExploitTechnical DescriptionThird Party Advisory
- https://github.com/kobezzza/Collection/blob/be32c48e68f49d3be48a58e929d1ab8ff1d2Broken Link
- https://github.com/kobezzza/Collection/commit/d3d937645f62f37d3115d6aa90bb510fd8Patch
- https://github.com/kobezzza/Collection/issues/27ExploitIssue TrackingPatch
- https://github.com/kobezzza/Collection/releases/tag/v6.8.1PatchRelease Notes
- https://security.snyk.io/vuln/SNYK-JS-COLLECTIONJS-3185148ExploitTechnical DescriptionThird Party Advisory
FAQ
What is CVE-2023-26113?
CVE-2023-26113 is a vulnerability with a CVSS score of 7.5 (HIGH). Versions of the package collection.js before 6.8.1 are vulnerable to Prototype Pollution via the extend function in Collection.js/dist/node/iterators/extend.js.
How severe is CVE-2023-26113?
CVE-2023-26113 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-26113?
Check the references section above for vendor advisories and patch information. Affected products include: Collection.Js Project Collection.Js.