Medium severity6.5GHSA Advisory· Published Feb 5, 2025· Updated Jun 17, 2026
CVE-2024-57082
CVE-2024-57082
Description
A prototype pollution in the lib.createUploader function of @rpldy/uploader v1.8.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@rpldy/uploadernpm | < 1.9.1 | 1.9.1 |
Affected products
2- Range: < 1.9.1
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-pc47-g7gv-4gpwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-57082ghsaADVISORY
- gist.github.com/tariqhawis/708e518de0c3b5af7430ec774f68f315nvdWEB
- github.com/rpldy/react-uploady/commit/386e0a80c428eb988e89fd2acf9bb0b786ac8028ghsaWEB
- github.com/rpldy/react-uploady/releases/tag/v1.9.1ghsaWEB
News mentions
0No linked articles in our index yet.