{"id":"CVE-2021-3766","aliases":["GHSA-r659-8xfp-j327"],"url":"https://o3.security/vulnerability/CVE-2021-3766","summary":"objection.js Prototype Pollution vulnerability","details":"objection.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')","published":"2021-09-06T12:15:08.177Z","modified":"2026-07-08T22:14:43.571904Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"objection","fixedVersion":"2.2.16"}],"fix":{"url":"https://github.com/Vincit/objection.js/commit/46b842a6bc897198b83f41ac85c92864b991d7e9","label":"Vincit/objection.js@46b842a"},"references":[{"type":"FIX","url":"https://github.com/Vincit/objection.js/commit/46b842a6bc897198b83f41ac85c92864b991d7e9"},{"type":"FIX","url":"https://huntr.dev/bounties/c98e0f0e-ebf2-4072-be73-a1848ea031cc"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T22:14:43.571904Z"}}