VYPR
Medium severity5.3NVD Advisory· Published Jul 25, 2021· Updated Jun 17, 2026

CVE-2021-23413

CVE-2021-23413

Description

This affects the package jszip before 3.7.0. Crafting a new zip file with filenames set to Object prototype values (e.g __proto__, toString, etc) results in a returned object with a modified prototype instance.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
jszipnpm
>= 3.0.0, < 3.7.03.7.0
jszipnpm
< 2.7.02.7.0

Affected products

3

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.