High severity7.5OSV Advisory· Published May 1, 2022· Updated Jun 17, 2026
CVE-2022-22143
CVE-2022-22143
Description
The package convict before 6.2.2 are vulnerable to Prototype Pollution via the convict function due to missing validation of parentKey. Note: This vulnerability derives from an incomplete fix of another vulnerability
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
convictnpm | < 6.2.3 | 6.2.3 |
Affected products
2- Range: v0.2.0, v0.2.1, v0.2.2, …
Patches
Vulnerability mechanics
References
9- github.com/mozilla/node-convict/commit/3b86be087d8f14681a9c889d45da7fe3ad9cd880nvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-CONVICT-2340604nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-x2w5-725j-gf2gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-22143ghsaADVISORY
- github.com/mozilla/node-convict/blob/5eb1314f85346760a3c31cb14510f2f0af11d0d3/packages/convict/src/main.js%23L569nvdBroken LinkWEB
- github.com/mozilla/node-convict/pull/384ghsaWEB
- github.com/mozilla/node-convict/releases/tag/v6.2.2ghsaWEB
- github.com/mozilla/node-convict/security/advisories/GHSA-x2w5-725j-gf2gghsaWEB
- www.huntr.dev/bounties/1-npm-convictghsaWEB
News mentions
0No linked articles in our index yet.