High severity7.3NVD Advisory· Published Jan 21, 2022· Updated Jun 17, 2026
CVE-2021-23518
CVE-2021-23518
Description
The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the object is used to create the cached relative path. When using the origin path as __proto__, the attribute of the object is accessed instead of a path. Note: This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-CACHEDPATHRELATIVE-72573
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
cached-path-relativenpm | < 1.1.0 | 1.1.0 |
Affected products
2- cached-path-relative/cached-path-relativedescription
Patches
Vulnerability mechanics
References
6- github.com/ashaffer/cached-path-relative/commit/40c73bf70c58add5aec7d11e4f36b93d144bb760nvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2348246nvdExploitIssue TrackingPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-CACHEDPATHRELATIVE-2342653nvdExploitIssue TrackingPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-wg6g-ppvx-927hghsaADVISORY
- lists.debian.org/debian-lts-announce/2022/12/msg00006.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-23518ghsaADVISORY
News mentions
0No linked articles in our index yet.