Medium severity6.5NVD Advisory· Published Mar 17, 2022· Updated Jun 17, 2026
CVE-2021-23771
CVE-2021-23771
Description
This affects all versions of package notevil; all versions of package argencoders-notevil. It is vulnerable to Sandbox Escape leading to Prototype pollution. The package fails to restrict access to the main context, allowing an attacker to add or modify an object's prototype. Note: This vulnerability derives from an incomplete fix in SNYK-JS-NOTEVIL-608878.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
notevilnpm | <= 1.3.3 | — |
argencoders-notevilnpm | <= 2.5.0 | — |
Affected products
4- ghsa-coords2 versions
<= 1.3.3+ 1 more
- (no CPE)range: <= 1.3.3
- (no CPE)range: <= 2.5.0
- cpe:2.3:a:argencoders-notevil_project:argencoders-notevil:*:*:*:*:*:node.js:*:*Range: <=2.5.0
Patches
Vulnerability mechanics
References
4- snyk.io/vuln/SNYK-JS-ARGENCODERSNOTEVIL-2388587nvdExploitThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-NOTEVIL-2385946nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-8g4m-cjm2-96wqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-23771ghsaADVISORY
News mentions
0No linked articles in our index yet.