High severity7.5NVD Advisory· Published Mar 25, 2024· Updated Jun 17, 2026
CVE-2024-21505
CVE-2024-21505
Description
Versions of the package web3-utils before 4.2.1 are vulnerable to Prototype Pollution via the utility functions format and mergeDeep, due to insecure recursive merge. An attacker can manipulate an object's prototype, potentially leading to the alteration of the behavior of all objects inheriting from the affected prototype by passing specially crafted input to these functions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
web3-utilsnpm | >= 4.0.1, < 4.2.1 | 4.2.1 |
Affected products
1Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-2g4c-8fpm-c46vghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-21505ghsaADVISORY
- github.com/web3/web3.js/commit/8ed041c6635d807b3da8960ad49e125e3d1b0e80nvdWEB
- github.com/web3/web3.js/security/advisories/GHSA-2g4c-8fpm-c46vghsaWEB
- security.snyk.io/vuln/SNYK-JS-WEB3UTILS-6229337nvdWEB
News mentions
0No linked articles in our index yet.