{"id":"CVE-2019-10781","aliases":["GHSA-r24h-634p-m72x","SNYK-JS-SCHEMAINSPECTOR-536970"],"url":"https://o3.security/vulnerability/CVE-2019-10781","summary":"Validation Bypass in schema-inspector","details":"In schema-inspector before 1.6.9, a maliciously crafted JavaScript object can bypass the `sanitize()` and the `validate()` function used within schema-inspector.","published":"2020-01-22T14:15:11.497Z","modified":"2026-08-27T08:14:58.150554Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"schema-inspector","fixedVersion":"1.6.9"}],"fix":{"url":"https://github.com/Atinux/schema-inspector/commit/345a7b2eed11bb6128421150d65f4f83fdbb737d","label":"Atinux/schema-inspector@345a7b2"},"references":[{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-JS-SCHEMAINSPECTOR-536970"},{"type":"FIX","url":"https://github.com/Atinux/schema-inspector/commit/345a7b2eed11bb6128421150d65f4f83fdbb737d"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T08:14:58.150554Z"}}