Critical severity9.8NVD Advisory· Published Mar 28, 2025· Updated Jun 17, 2026
CVE-2024-38988
CVE-2024-38988
Description
alizeait unflatto <= 1.0.2 was discovered to contain a prototype pollution via the method exports.unflatto at /dist/index.js. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@alizeait/unflattonpm | < 1.0.3 | 1.0.3 |
Affected products
3Patches
Vulnerability mechanics
References
6- gist.github.com/mestrtee/4c5dfb66bea377889c44dd6c8af28713nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-q8jq-4rm5-4hm5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-38988ghsaADVISORY
- github.com/alizeait/unflatto/commit/3c1b120f1dcd44eefe07d4a5022e1baa3c7164d3ghsaWEB
- github.com/alizeait/unflatto/issues/32ghsaWEB
- github.com/alizeait/unflatto/security/advisories/GHSA-q8jq-4rm5-4hm5ghsaWEB
News mentions
0No linked articles in our index yet.