CVE-2019-10808 is a prototype pollution vulnerability affecting utilitify prior to version 1.0.3, allowing attackers to modify or add properties to the Object.prototype via the merge method. This high-severity flaw carries a CVSS score of 8.8, indicating a critical risk due to its low attack complexity and potential for complete compromise of confidentiality, integrity, and availability. While no public exploits (Metasploit, Nuclei, ExploitDB) are currently available, and there's minimal community discussion or media coverage, the vulnerability's nature makes it a significant concern for affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.3CPE matchmatch criteria | cpe:2.3:a:xcritical.software:utilitify:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.