{"id":"CVE-2015-8857","aliases":["GHSA-34r7-q49f-h37c"],"url":"https://o3.security/vulnerability/CVE-2015-8857","summary":"Incorrect Handling of Non-Boolean Comparisons During Minification in uglify-js","details":"The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expressions, which might allow attackers to bypass security mechanisms or possibly have unspecified other impact by leveraging improperly rewritten Javascript.","published":"2017-01-23T21:59:00Z","modified":"2026-04-10T03:45:36.752998Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"uglify-js","fixedVersion":"2.4.24"},{"ecosystem":"RubyGems","name":"uglifier","fixedVersion":"2.7.2"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2016/04/20/11"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/96410"},{"type":"ADVISORY","url":"https://nodesecurity.io/advisories/39"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2016/04/20/11"},{"type":"EVIDENCE","url":"https://nodesecurity.io/advisories/39"},{"type":"FIX","url":"https://nodesecurity.io/advisories/39"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-10T03:45:36.752998Z"}}