← Back to browse · API

CVE-2024-38999

Severity
CRITICAL
CVSS
10.0
EPSS
0.00756
Risk score
40.26
CISA KEV
No
PoC
No
Published
2024-07-01
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2024-2445, GHSA-X3M3-4WPV-5VGC
Products
n/a:n/a n/a
Sources
euvd EUVD-2024-2445

Description

jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

References