A AegiFlow
HIGHCVSS 7.8

CVE-2024-21489

CVE-2024-21489 updated by NVD

Modified
2026-08-12
Sources
nvd

Summary

Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to missing check if the attribute resolves to the object prototype.

References

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.