Critical severity9.8NVD Advisory· Published Aug 16, 2023· Updated Jul 9, 2026
CVE-2023-38894
CVE-2023-38894
Description
A Prototype Pollution issue in Cronvel Tree-kit v.0.7.4 and before allows a remote attacker to execute arbitrary code via the extend function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
tree-kitnpm | < 0.7.5 | 0.7.5 |
Affected products
3- Cronvel/Tree-kitdescription
Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.