Impact
The vulnerability arises from the set() function in the traverse package, which allows an attacker controlling an untrusted path argument to write properties onto built‑in JavaScript prototypes such as String.prototype, Number.prototype, or Boolean.prototype. This prototype pollution (CWE‑1321) means that the application may unintentionally alter the behavior of every object that relies on those prototypes, potentially enabling arbitrary code execution, tampering of application logic, or denial of service.
Affected Systems
The affected product is the npm package "traverse", authored by ljharb (GitHub repository js‑traverse). All releases from 0.3.6 through 0.3.9, 0.4.0 through 0.4.6, 0.5.0 through 0.5.2, and 0.6.0 through 0.6.11 are vulnerable. The latest patched releases are 0.3.10, 0.4.7, 0.5.3, and 0.6.12 or newer.
Risk and Exploitability
The CVSS score of 6.9 indicates a high severity impact that can be achieved when the set() call receives untrusted input. EPSS is not available, so the exploitation probability cannot be quantified, and the vulnerability is not currently listed in the CISA KEV catalogue. Based on the description, the attack vector is likely remote or network‑based if an attacker can supply input that reaches the set() function, for example through a REST endpoint or a plugin that forwards user data to traverse. A successful exploit would enable the attacker to inject properties into prototypes, which may subsequently lead to arbitrary code execution or data tampering.
OpenCVE Enrichment