CVE-2021-44906Critical· 9.8▾ AbyssalPoC availableMinimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 53.9 · likelihood 0.9 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
4.6%
1 GitHub repo (last check)
Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
minimist < 1.2.6Upgrade past the affected range:
minimist 1.2.6Connected by shared product, vendor, weakness, or advisory.
CVE-2020-7598Medium· 5.6minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
CVE-2021-23383Medium· 5.6The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.
CVE-2011-10019Critical· 9.8Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality
CVE-2025-34146High· 7.0A prototype pollution vulnerability exists in @nyariv/sandboxjs versions <= 0.8.23, allowing attackers to inject arbitrary properties into Object.prototype via crafted JavaScript code
CVE-2026-105844Critical· 9.3Payload is a free and open source headless content management system
CVE-2026-104849Critical· 9.5Tinypool is a minimal Node.js worker thread pool implementation