Critical severity9.8NVD Advisory· Published Sep 13, 2021· Updated Jun 17, 2026
CVE-2021-3666
CVE-2021-3666
Description
body-parser-xml is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
body-parser-xmlnpm | < 2.0.3 | 2.0.3 |
Affected products
3- cpe:2.3:a:xml_body_parser_project:xml_body_parser:*:*:*:*:*:node.js:*:*Range: <2.0.3
- fiznool/fiznool/body-parser-xmlv5Range: unspecified
Patches
Vulnerability mechanics
References
4- github.com/fiznool/body-parser-xml/commit/d46ca622560f7c9a033cd9321c61e92558150d63nvdPatchThird Party AdvisoryWEB
- huntr.dev/bounties/1-other-fiznool/body-parser-xmlnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-2ghc-6v89-pw9jghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-3666ghsaADVISORY
News mentions
0No linked articles in our index yet.