{"id":"CVE-2021-23624","aliases":["GHSA-6g47-63mv-qpgh","SNYK-JS-DOTTY-1577292"],"url":"https://o3.security/vulnerability/CVE-2021-23624","summary":"Prototype Pollution in dotty","details":"This affects the package dotty before 0.1.2. A type confusion vulnerability can lead to a bypass of CVE-2021-25912 when the user-provided keys used in the path parameter are arrays.","published":"2021-11-03T18:15:08.130Z","modified":"2026-07-08T06:50:01.172373138Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.01242,"percentile":0.66456,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"dotty","fixedVersion":"0.1.2"}],"fix":{"url":"https://github.com/deoxxa/dotty/commit/88f61860dcc274a07a263c32cbe9d44c24ef02d7","label":"deoxxa/dotty@88f6186"},"references":[{"type":"FIX","url":"https://github.com/deoxxa/dotty/commit/88f61860dcc274a07a263c32cbe9d44c24ef02d7"},{"type":"FIX","url":"https://snyk.io/vuln/SNYK-JS-DOTTY-1577292"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T06:50:01.172373138Z"}}