High severity7.5OSV Advisory· Published May 13, 2022· Updated Jun 17, 2026
CVE-2022-21190
CVE-2022-21190
Description
This affects the package convict before 6.2.3. This is a bypass of CVE-2022-22143. The fix introduced, relies on the startsWith method and does not prevent the vulnerability: before splitting the path, it checks if it starts with __proto__ or this.constructor.prototype. To bypass this check it's possible to prepend the dangerous paths with any string value followed by a dot, like for example foo.__proto__ or foo.this.constructor.prototype.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
convictnpm | < 6.2.3 | 6.2.3 |
Affected products
2- Range: v0.2.0, v0.2.1, v0.2.2, …
Patches
Vulnerability mechanics
References
7- github.com/mozilla/node-convict/blob/3b86be087d8f14681a9c889d45da7fe3ad9cd880/packages/convict/src/main.js%23L571nvdBroken LinkPatchThird Party AdvisoryWEB
- github.com/mozilla/node-convict/commit/1ea0ab19c5208f66509e1c43b0d0f21c1fd29b75nvdPatchTool SignatureWEB
- gist.github.com/dellalibera/cebce20e51410acebff1f46afdc89808nvdExploitThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-CONVICT-2774757nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-jjf5-wx3j-3fv7ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-21190ghsaADVISORY
- github.com/mozilla/node-convict/blob/master/CHANGELOG.md%23623---2022-05-07nvdBroken LinkRelease NotesTool SignatureWEB
News mentions
0No linked articles in our index yet.