CVE-2021-21368 is a prototype poisoning vulnerability affecting msgpack5, a MessagePack implementation for Node.js and browsers, in versions prior to 3.6.1, 4.5.1, and 5.2.1. An attacker can craft MessagePack data containing a "__proto__" key, causing the decoded object's prototype to be set to an arbitrary msgpack5 value. This can lead to unexpected type behavior, property access issues, and potential exceptions. The vulnerability has a CVSS v3.1 score of 8.8 (High), indicating a high severity. It can be exploited remotely with low attack complexity and no user interaction, potentially leading to high impact on confidentiality, integrity, and availability. While it's a limited form of prototype poisoning, it could be leveraged in conjunction with other bugs. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, suggesting low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.6.1CPE matchmatch criteria | cpe:2.3:a:msgpack5_project:msgpack5:*:*:*:*:*:node.js:*:* | ||
>= 4.0.0, < 4.5.1CPE matchmatch criteria | cpe:2.3:a:msgpack5_project:msgpack5:*:*:*:*:*:node.js:*:* | ||
>= 5.0.0, < 5.2.1CPE matchmatch criteria | cpe:2.3:a:msgpack5_project:msgpack5:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.