{"id":"CVE-2019-20149","aliases":["GHSA-6c8f-qphg-qjgp"],"url":"https://o3.security/vulnerability/CVE-2019-20149","summary":"Validation Bypass in kind-of","details":"ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflicting name, as demonstrated by 'constructor': {'name':'Symbol'}. Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection result.","published":"2019-12-30T19:15:11.910Z","modified":"2026-07-08T19:02:27.475280Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"kind-of","fixedVersion":"6.0.3"}],"fix":{"url":"https://github.com/jonschlinkert/kind-of/pull/31","label":"jonschlinkert/kind-of#31"},"references":[{"type":"REPORT","url":"https://github.com/jonschlinkert/kind-of/issues/30"},{"type":"FIX","url":"https://github.com/jonschlinkert/kind-of/pull/31"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T19:02:27.475280Z"}}