Critical severity9.8NVD Advisory· Published Mar 9, 2021· Updated Jun 17, 2026
CVE-2021-25915
CVE-2021-25915
Description
Prototype pollution vulnerability in 'changeset' versions 0.0.1 through 0.2.5 allows an attacker to cause a denial of service and may lead to remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
changesetnpm | >= 0.0.1, < 0.2.5 | 0.2.5 |
Affected products
3- changeset/changesetdescription
- cpe:2.3:a:changeset_project:changeset:*:*:*:*:*:node.js:*:*Range: >=0.0.1,<0.2.6
Patches
Vulnerability mechanics
References
5- github.com/eugeneware/changeset/commit/9e588844edbb9993b32e7366cc799262b4447f99nvdPatchThird Party AdvisoryWEB
- www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25915nvdExploitThird Party Advisory
- github.com/advisories/GHSA-2gqw-q9r9-7f79ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-25915ghsaADVISORY
- web.archive.org/web/20210323102946/https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25915ghsaWEB
News mentions
0No linked articles in our index yet.