Description
The package jointjs before 3.3.0 are vulnerable to Denial of Service (DoS) via the unsetByPath function.
Recommendation
Update the jointjs package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.3.0
- Patched version(s): 3.3.0
References
Could your website be exposed too?
SmartScanner can check your website for Denial of Service (DoS) via the unsetByPath function in jsjoints and gives you actionable findings to investigate.
Start a free scanRelated Issues
- jsPDF Vulnerable to Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder - CVE-2026-24133
- Cube Core is vulnerable to Denial of Service (DoS) via crafted request - CVE-2026-25957
- cookiejar Regular Expression Denial of Service via Cookie.parse function - CVE-2022-25901
- ExifReader is vulnerable to denial of service via crafted ICC `mluc` tag - CVE-2026-8813
You might also like:
See something that needs correcting? Let us knowUpdated February 01, 2023


