Critical severity9.8NVD Advisory· Published Feb 17, 2022· Updated Jun 17, 2026
CVE-2022-22912
CVE-2022-22912
Description
Prototype pollution vulnerability via .parse() in Plist before v3.0.4 allows attackers to cause a Denial of Service (DoS) and may lead to remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
plistnpm | < 3.0.5 | 3.0.5 |
Affected products
3- Plist/Plistdescription
Patches
Vulnerability mechanics
References
5- github.com/TooTallNate/plist.js/issues/114nvdExploitIssue TrackingPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-4cpg-3vgw-4877ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-22912ghsaADVISORY
- github.com/TooTallNate/plist.js/commit/96e2303d059e6be0c9e0c4773226d14b4758de52ghsaWEB
- github.com/TooTallNate/plist.js/pull/118ghsaWEB
News mentions
0No linked articles in our index yet.