{"id":"CVE-2021-23370","aliases":["GHSA-p3hc-fv2j-rp68"],"url":"https://o3.security/vulnerability/CVE-2021-23370","summary":"Prototype Pollution in swiper","details":"This affects the package swiper before 6.5.1.","published":"2021-04-12T14:15:14.537Z","modified":"2026-07-08T21:27:21.573831Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":5,"affectedPackages":[{"ecosystem":"npm","name":"swiper","fixedVersion":"6.5.1"}],"fix":{"url":"https://github.com/nolimits4web/swiper/commit/9dad2739b7474f383474773d5ab898a0c29ac178","label":"nolimits4web/swiper@9dad273"},"references":[{"type":"FIX","url":"https://github.com/nolimits4web/swiper/commit/9dad2739b7474f383474773d5ab898a0c29ac178"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1244698"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1244699"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBNOLIMITS4WEB-1244697"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1244696"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JS-SWIPER-1088062"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T21:27:21.573831Z"}}