High severity7.5NVD Advisory· Published Oct 6, 2023· Updated Jun 17, 2026
CVE-2023-45282
CVE-2023-45282
Description
In NASA Open MCT (aka openmct) before 3.1.0, prototype pollution can occur via an import action.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
openmctnpm | <= 3.0.2 | — |
Affected products
3- NASA/Open MCTdescription
Patches
Vulnerability mechanics
References
8- github.com/nasa/openmct/pull/7094/commits/545a1770c523ecc3410dca884c6809d5ff0f9d52nvdPatchWEB
- github.com/advisories/GHSA-4xcx-cwrq-w792ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-45282ghsaADVISORY
- www.linkedin.com/pulse/prototype-pollution-nasas-open-mct-cve-2023-45282nvdThird Party AdvisoryWEB
- github.com/nasa/openmct/commit/2243381d527c0d84cc48e9ace78be7cda5363612ghsaWEB
- github.com/nasa/openmct/compare/v3.0.2...v3.1.0nvdProductWEB
- nasa.github.io/openmctghsaWEB
- nasa.github.io/openmct/nvdProduct
News mentions
0No linked articles in our index yet.