{"id":"CVE-2024-21489","aliases":["GHSA-34q8-jcq6-mc37"],"url":"https://o3.security/vulnerability/CVE-2024-21489","summary":"uPlot Prototype Pollution vulnerability","details":"Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to missing check if the attribute resolves to the object prototype.","published":"2024-10-01T05:00:02.644Z","modified":"2026-07-15T01:49:14.024383118Z","cvss":{"score":8.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L/E:P"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"uplot","fixedVersion":"1.6.31"}],"fix":{"url":"https://github.com/leeoniya/uPlot/commit/5756e3e9b91270b303157e14bd0174311047d983","label":"leeoniya/uPlot@5756e3e"},"references":[{"type":"WEB","url":"https://github.com/leeoniya/uPlot/blob/c52e5001c1d959a99ac495a53e4deca5c44464d2/src/utils.js%23L437-L452"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-UPLOT-6209224"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/21xxx/CVE-2024-21489.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-21489"},{"type":"FIX","url":"https://github.com/leeoniya/uPlot/commit/5756e3e9b91270b303157e14bd0174311047d983"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:14.024383118Z"}}