VYPR
High severity7.7NVD Advisory· Published Apr 29, 2021· Updated Jun 17, 2026

CVE-2021-21414

CVE-2021-21414

Description

Prisma is an open source ORM for Node.js & TypeScript. As of today, we are not aware of any Prisma users or external consumers of the @prisma/sdk package who are affected by this security vulnerability. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. It only affects the getPackedPackage function and this function is not advertised and only used for tests & building our CLI, no malicious code was found after checking our codebase.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
@prisma/sdknpm
< 2.20.02.20.0

Affected products

3
  • Prisma/Prisma2 versions
    cpe:2.3:a:prisma:prisma:*:*:*:*:*:node.js:*:*+ 1 more
    • cpe:2.3:a:prisma:prisma:*:*:*:*:*:node.js:*:*range: <2.20.0
    • (no CPE)range: < 2.20.0
  • ghsa-coords
    Range: < 2.20.0

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.