Critical severity9.8NVD Advisory· Published Oct 20, 2022· Updated Jun 17, 2026
CVE-2022-37598
CVE-2022-37598
Description
Prototype pollution vulnerability in function DEFNODE in ast.js in mishoo UglifyJS 3.13.2 via the name variable in ast.js. NOTE: the vendor considers this an invalid report.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:uglifyjs_project:uglifyjs:3.13.2:*:*:*:*:node.js:*:*
- mishoo/UglifyJSdescription
Patches
Vulnerability mechanics
References
4- github.com/mishoo/UglifyJS/blob/352a944868b09c9ce3121a49d4a0bf0afe370a35/lib/ast.jsnvdExploitThird Party Advisory
- github.com/mishoo/UglifyJS/blob/352a944868b09c9ce3121a49d4a0bf0afe370a35/lib/ast.jsnvdExploitThird Party Advisory
- github.com/mishoo/UglifyJS/issues/5699nvdIssue TrackingThird Party Advisory
- github.com/mishoo/UglifyJS/issues/5721nvdThird Party Advisory
News mentions
0No linked articles in our index yet.