cached-path-relative
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting cached-path-relativepage 1 of 1
- CVE-2018-16472HIGHCVSS 7.5EG 7.5✓ Fixed in 1.0.22018-11-06
A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inherited by all the JS objects through the prototype chain causing a DoS attack.
- CVE-2021-23518HIGHCVSS 7.3EG 7.3✓ Fixed in 1.1.02022-01-21
The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype pro…
Check whether cached-path-relative is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for cached-path-relative CVEs against the assets you own.
Start Free Scan →