VYPR
High severity7.5OSV Advisory· Published Dec 18, 2024· Updated Jun 17, 2026

CVE-2024-21548

CVE-2024-21548

Description

Versions of the package bun after 0.0.12 and before 1.1.30 are vulnerable to Prototype Pollution due to improper input sanitization. An attacker can exploit this vulnerability through Bun's APIs that accept objects. Note: This issue relates to the widely known and actively developed 'Bun' JavaScript runtime. The bun package on NPM at versions 0.0.12 and below belongs to a different and older project that happened to claim the 'bun' name in the past.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Oven Sh/BunOSV2 versions
    09-07-231835-2021, build-8, bun-build-, …+ 1 more
    • (no CPE)range: 09-07-231835-2021, build-8, bun-build-, …
    • (no CPE)range: >0.0.12,<1.1.30
  • Npm/bunllm-create
    Range: <=0.0.12

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.