{"id":"CVE-2019-10792","aliases":["GHSA-8h84-8j4f-p97q","SNYK-JS-BODYMEN-548897"],"url":"https://o3.security/vulnerability/CVE-2019-10792","summary":"Injection in bodymen","details":"bodymen before 1.1.1 is vulnerable to Prototype Pollution. The handler function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.","published":"2020-02-18T16:15:10.233Z","modified":"2026-08-14T09:05:29.424194Z","cvss":{"score":6.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"bodymen","fixedVersion":"1.1.1"}],"fix":{"url":"https://github.com/diegohaz/bodymen/commit/5d52e8cf360410ee697afd90937e6042c3a8653b","label":"diegohaz/bodymen@5d52e8c"},"references":[{"type":"FIX","url":"https://github.com/diegohaz/bodymen/commit/5d52e8cf360410ee697afd90937e6042c3a8653b"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JS-BODYMEN-548897"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-14T09:05:29.424194Z"}}