CVE-2021-23413 affects jszip versions prior to 3.7.0, allowing an attacker to craft a malicious zip file with filenames matching Object prototype values, leading to prototype pollution. This vulnerability has a CVSS score of 5.3 (Medium), indicating a low impact on availability and no impact on confidentiality or integrity, with no user interaction required for exploitation. There is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.7.0CPE matchmatch criteria | cpe:2.3:a:jszip_project:jszip:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Third-Party Package Updates in Splunk AppDynamics On-Premises Enterprise Console - August 2025
Aug 6, 2025jszip Vulnerable to Prototype Pollution
Aug 10, 2021jszip: crafting a new zip file with filenames set to object prototype values results in a returned object with a modified prototype instance
Apr 18, 2021