VYPR
Critical severity9.8NVD Advisory· Published Oct 12, 2022· Updated Jun 17, 2026

CVE-2022-37601

CVE-2022-37601

Description

Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
loader-utilsnpm
>= 2.0.0, < 2.0.32.0.3
loader-utilsnpm
< 1.4.11.4.1

Affected products

10

Patches

Vulnerability mechanics

References

18

News mentions

0

No linked articles in our index yet.