Critical severity9.8NVD Advisory· Published Oct 12, 2022· Updated Jun 17, 2026
CVE-2022-37601
CVE-2022-37601
Description
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
loader-utilsnpm | >= 2.0.0, < 2.0.3 | 2.0.3 |
loader-utilsnpm | < 1.4.1 | 1.4.1 |
Affected products
10- webpack/loader-utilsdescription
- osv-coords7 versionspkg:apk/chainguard/jitsucom-jitsupkg:apk/chainguard/jitsucom-jitsu-consolepkg:apk/chainguard/jitsucom-jitsu-rotorpkg:apk/wolfi/jitsucom-jitsupkg:apk/wolfi/jitsucom-jitsu-consolepkg:apk/wolfi/jitsucom-jitsu-rotorpkg:npm/loader-utils
< 2.11.0-r6+ 6 more
- (no CPE)range: < 2.11.0-r6
- (no CPE)range: < 2.11.0-r6
- (no CPE)range: < 2.11.0-r6
- (no CPE)range: < 2.11.0-r6
- (no CPE)range: < 2.11.0-r6
- (no CPE)range: < 2.11.0-r6
- (no CPE)range: >= 2.0.0, < 2.0.3
Patches
Vulnerability mechanics
References
18- github.com/webpack/loader-utils/issues/212nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/xmldom/xmldom/issues/436nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-76p3-8jx3-jpfqghsaADVISORY
- github.com/webpack/loader-utils/issues/212nvdIssue TrackingThird Party AdvisoryWEB
- lists.debian.org/debian-lts-announce/2022/12/msg00044.htmlnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-37601ghsaADVISORY
- users.encs.concordia.ca/~mmannan/publications/JS-vulnerability-aisaccs2022.pdfnvdTechnical DescriptionWEB
- dl.acm.org/doi/abs/10.1145/3488932.3497769nvdTechnical DescriptionWEB
- dl.acm.org/doi/pdf/10.1145/3488932.3497769nvdTechnical DescriptionWEB
- github.com/webpack/loader-utils/blob/d9f4e23cf411d8556f8bac2d3bf05a6e0103b568/lib/parseQuery.jsnvdProduct
- github.com/webpack/loader-utils/blob/d9f4e23cf411d8556f8bac2d3bf05a6e0103b568/lib/parseQuery.jsnvdProduct
- github.com/webpack/loader-utils/commit/4504e34c4796a5836ef70458327351675aed48a5ghsaWEB
- github.com/webpack/loader-utils/commit/a93cf6f4702012030f6b5ee8340d5c95ec1c7d4cghsaWEB
- github.com/webpack/loader-utils/commit/f4e48a232fae900237c3e5ff7b57ce9e1c734de1ghsaWEB
- github.com/webpack/loader-utils/pull/217ghsaWEB
- github.com/webpack/loader-utils/pull/220ghsaWEB
- github.com/webpack/loader-utils/releases/tag/v1.4.1ghsaWEB
- github.com/webpack/loader-utils/releases/tag/v2.0.3ghsaWEB
News mentions
0No linked articles in our index yet.