Vulnerability Details CVE-2021-26505
Prototype pollution vulnerability in MrSwitch hello.js version 1.18.6, allows remote attackers to execute arbitrary code via hello.utils.extend function.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 64.2%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2021-26505
-
cpe:2.3:a:hello.js_project:hello.js:1.18.6