{"id":"CVE-2021-23444","aliases":["GHSA-f3pp-32qc-36w4"],"url":"https://o3.security/vulnerability/CVE-2021-23444","summary":"Prototype Pollution in jointjs","details":"This affects the package jointjs before 3.4.2. A type confusion vulnerability can lead to a bypass of CVE-2020-28480 when the user-provided keys used in the path parameter are arrays in the setByPath function.","published":"2021-09-21T17:15:09.390Z","modified":"2026-07-09T01:30:13.974472Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":3,"affectedPackages":[{"ecosystem":"npm","name":"jointjs","fixedVersion":"3.4.2"}],"fix":{"url":"https://github.com/clientIO/joint/commit/e5bf89efef6d5ea572d66870ffd86560de7830a8","label":"clientIO/joint@e5bf89e"},"references":[{"type":"ADVISORY","url":"https://github.com/clientIO/joint/pull/1514"},{"type":"ADVISORY","url":"https://github.com/clientIO/joint/releases/tag/v3.4.2"},{"type":"FIX","url":"https://github.com/clientIO/joint/commit/e5bf89efef6d5ea572d66870ffd86560de7830a8"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1655817"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1655816"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JS-JOINTJS-1579578"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T01:30:13.974472Z"}}