VYPR
Medium severity5.3NVD Advisory· Published Feb 24, 2020· Updated Jun 17, 2026

CVE-2019-10798

CVE-2019-10798

Description

rdf-graph-array through 0.3.0-rc6 manipulation of JavaScript objects resutling in Prototype Pollution. The rdf.Graph.prototype.add method could be tricked into adding or modifying properties of Object.prototype.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
rdf-graph-arraynpm
<= 0.3.0-rc6

Affected products

5
  • cpe:2.3:a:rdf-graph-array_project:rdf-graph-array:0.3.0:-:*:*:*:node.js:*:*+ 2 more
    • cpe:2.3:a:rdf-graph-array_project:rdf-graph-array:0.3.0:-:*:*:*:node.js:*:*
    • cpe:2.3:a:rdf-graph-array_project:rdf-graph-array:0.3.0:rc1:*:*:*:node.js:*:*
    • cpe:2.3:a:rdf-graph-array_project:rdf-graph-array:0.3.0:rc6:*:*:*:node.js:*:*
  • rdf-graph-array/rdf-graph-arraydescription
  • ghsa-coords
    Range: <= 0.3.0-rc6

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.