Description
The package jointjs before 3.3.0 are vulnerable to Denial of Service (DoS) via the unsetByPath function.
Recommendation
Update the jointjs package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.3.0
- Patched version(s): 3.3.0
References
Related Issues
- jsPDF Vulnerable to Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder - CVE-2026-24133
- Cube Core is vulnerable to Denial of Service (DoS) via crafted request - CVE-2026-25957
- cookiejar Regular Expression Denial of Service via Cookie.parse function - CVE-2022-25901
- ExifReader is vulnerable to denial of service via crafted ICC `mluc` tag - CVE-2026-8813
You might also like:
- Tags:
- npm
- jointjs
Anything's wrong? Let us know Last updated on February 01, 2023


