Medium severity5.6NVD Advisory· Published Aug 27, 2021· Updated Jun 17, 2026
CVE-2021-23434
CVE-2021-23434
Description
This affects the package object-path before 0.11.6. A type confusion vulnerability can lead to a bypass of CVE-2020-15256 when the path components used in the path parameter are arrays. In particular, the condition currentPath === '__proto__' returns false if currentPath is ['__proto__']. This is because the === operator returns always false when the type of the operands is different.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
object-pathnpm | < 0.11.6 | 0.11.6 |
Affected products
4- cpe:2.3:a:object-path_project:object-path:*:*:*:*:*:node.js:*:*Range: <0.11.6
- object-path/object-pathdescription
Patches
Vulnerability mechanics
References
6- github.com/mariocasciaro/object-path/commit/7bdf4abefd102d16c163d633e8994ef154cab9ebnvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1570423nvdExploitThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-OBJECTPATH-1569453nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-v39p-96qg-c8rfghsaADVISORY
- lists.debian.org/debian-lts-announce/2023/01/msg00031.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-23434ghsaADVISORY
News mentions
0No linked articles in our index yet.