{"id":"CVE-2024-38985","aliases":[],"url":"https://o3.security/vulnerability/CVE-2024-38985","summary":"depath and cool-path vulnerable to Prototype Pollution via `set()` Method","details":"janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() method at setIn (lib/index.js:90). This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.","published":"2025-03-28T21:30:46Z","modified":"2025-03-31T16:24:38.764249Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"depath","fixedVersion":null},{"ecosystem":"npm","name":"cool-path","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-38985"},{"type":"WEB","url":"https://github.com/janryWang/depath/issues/11"},{"type":"WEB","url":"https://gist.github.com/mestrtee/32c0a48023036e51918f6a098f21953d"},{"type":"PACKAGE","url":"https://github.com/janryWang/depath"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-03-31T16:24:38.764249Z"}}