ZÉROJOUR

The zero-day paper — printed from structured content, not scraped prose.
Permanent editionPublic dataset · Sanity GROQGHSA × CISA KEV
minimist (npm) · published 2022-03-18

Prototype Pollution in minimist

CVE-2021-44906 — CVSS 9.8/10. Fix: upgrade to 1.2.6.
Package
minimist
Ecosystem
npm
Vector
NETWORK
Complexity
LOW
Privileges
NONE
Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Minimist prior to 1.2.6 and 0.2.4 is vulnerable to Prototype Pollution via file `index.js`, function `setKey()` (lines 69-95).

Weakness classes: CWE-1321 (Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'))

Source: GHSA-xvch-5gv4-984h · GitHub Advisory Database (CC-BY-4.0) — printed from a structured Sanity dataset. ← Back to the front page

ZéroJour prints itself from a Sanity dataset of real advisories (GitHub Advisory Database, CC-BY-4.0; CISA KEV). No scraping, no keyword search — headlines are typed fields, scores are numbers, fixes are versions. The newsroom composes, a human approves.