High severity8.8NVD Advisory· Published Apr 23, 2021· Updated Jun 17, 2026
CVE-2021-20087
CVE-2021-20087
Description
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-deparam 0.5.1 allows a malicious user to inject properties into Object.prototype.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
jquery-deparamnpm | <= 0.5.3 | — |
Affected products
3- jquery-deparam/jquery-deparamdescription
- cpe:2.3:a:acemetrix:jquery-deparam:0.5.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- github.com/BlackFan/client-side-prototype-pollution/blob/master/pp/jquery-deparam.mdnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-xg68-chx2-253gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-20087ghsaADVISORY
- github.com/RetireJS/retire.js/blob/6da45fcb6a3425e55ee8181b2ac35168879bf086/repository/jsrepository-master.jsonnvdWEB
News mentions
0No linked articles in our index yet.