← Back to browse · API

CVE-2024-39008

Severity
CRITICAL
CVSS
10.0
EPSS
0.00918
Risk score
40.32
CISA KEV
No
PoC
No
Published
2024-07-01
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2024-2238, GHSA-3Q56-9CC2-46J4
Products
n/a:n/a n/a
Sources
euvd EUVD-2024-2238

Description

robinweser fast-loops v1.1.3 was discovered to contain a prototype pollution via the function objectMergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

References