CVE-2020-7598Medium· 5.6▾ TwilightPoC availableminimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 30.8 · likelihood 0.4 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.9%
1 GitHub repo (last check)
minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "proto" payload.
minimist < 1.2.2leap = 15.1Upgrade past the affected range:
minimist 1.2.2Connected by shared product, vendor, weakness, or advisory.
CVE-2021-44906Critical· 9.8Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
CVE-2021-23383Medium· 5.6The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.
CVE-2011-10019Critical· 9.8Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality
CVE-2025-34146High· 7.0A prototype pollution vulnerability exists in @nyariv/sandboxjs versions <= 0.8.23, allowing attackers to inject arbitrary properties into Object.prototype via crafted JavaScript code
CVE-2026-105844Critical· 9.3Payload is a free and open source headless content management system
CVE-2026-104849Critical· 9.5Tinypool is a minimal Node.js worker thread pool implementation