Medium severity5.3NVD Advisory· Published Jul 25, 2021· Updated Jun 17, 2026
CVE-2021-23413
CVE-2021-23413
Description
This affects the package jszip before 3.7.0. Crafting a new zip file with filenames set to Object prototype values (e.g __proto__, toString, etc) results in a returned object with a modified prototype instance.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
jszipnpm | >= 3.0.0, < 3.7.0 | 3.7.0 |
jszipnpm | < 2.7.0 | 2.7.0 |
Affected products
3- jszip/jszipdescription
Patches
Vulnerability mechanics
References
8- github.com/Stuk/jszip/commit/22357494f424178cb416cdb7d93b26dd4f824b36nvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1251499nvdExploitPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1251498nvdExploitPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-JSZIP-1251497nvdExploitPatchThird Party AdvisoryWEB
- github.com/Stuk/jszip/pull/766nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-jg8v-48h5-wgxgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-23413ghsaADVISORY
- github.com/Stuk/jszip/blob/master/lib/object.js%23L88nvdBroken LinkWEB
News mentions
0No linked articles in our index yet.