Description
json-schema before version 0.4.0 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes (‘Prototype Pollution’).
Recommendation
Update the json-schema package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.4.0
- Patched version(s): 0.4.0
References
- GHSA-896r-f27r-55mw
- huntr.dev
- lists.debian.org
- security.netapp.com
- CVE-2021-3918
- CWE-1321
- CWE-915
- CAPEC-310
- OWASP 2021-A6
- OWASP 2021-A8
Related Issues
- json-schema-editor-visual vulnerable to prototype pollution - CVE-2025-57320
- MrSwitch hello.js vulnerable to prototype pollution - CVE-2021-26505
- jszip Vulnerable to Prototype Pollution - CVE-2021-23413
- npm package rfc6902 vulnerable to Prototype Pollution - CVE-2021-4245
You might also like:
- Tags:
- npm
- json-schema
Anything's wrong? Let us know Last updated on January 17, 2025


