View all vulnerabilities

CVE-2022-37601

Prototype pollution in webpack loader-utils

Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils prior to version 2.0.3 via the name variable in parseQuery.js.

Patch Available

Fix available through Seal Security. No upgrade required, protect your application instantly.

Fix without upgrading
Vulnerability Details
Score
9.8
Score Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Versions
loader-utils >= 2.0.0 < 2.0.3; loader-utils < 1.4.1
Severity
Ecosystem
JavaScript
Publish Date
October 13, 2022
Modified Date
November 7, 2023