Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-23413

21
FAUCET Score

CVE-2021-23413 affects jszip versions prior to 3.7.0, allowing an attacker to craft a malicious zip file with filenames matching Object prototype values, leading to prototype pollution. This vulnerability has a CVSS score of 5.3 (Medium), indicating a low impact on availability and no impact on confidentiality or integrity, with no user interaction required for exploitation. There is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.7.0CPE matchmatch criteria
cpe:2.3:a:jszip_project:jszip:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
3.31%
Probability of exploitation in next 30 days
EPSS Percentile
87.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0331 is in the 83rd percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

github_advisorypatch availablevia nvd_reference
View patch
nodejspatch availablevia llm_extracted
Fixed in: 25.4.0
npmpatch availablevia ghsa
Product: jszipFixed in: 3.7.0
npmpatch availablevia ghsa
Product: jszipFixed in: 2.7.0
redhatend of lifevia redhat_api
Product: Migration Toolkit for ContainersFixed in: rhmtc/openshift-migration-ui-rhel8
redhatend of lifevia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-rhel8

Vendor Advisories (3)

nodejsllm-nodejs-9e1762a1939f642dCRITICAL

Third-Party Package Updates in Splunk AppDynamics On-Premises Enterprise Console - August 2025

Aug 6, 2025
npmGHSA-jg8v-48h5-wgxgmedium

jszip Vulnerable to Prototype Pollution

Aug 10, 2021
redhatCVE-2021-23413Moderate

jszip: crafting a new zip file with filenames set to object prototype values results in a returned object with a modified prototype instance

Apr 18, 2021

References

github.com / Stuk/jszip/blob/master/lib/object.js%23L88
Broken Link
github.com / Stuk/jszip/commit/22357494f424178cb416cdb7d93b26dd4f824b36
PatchThird Party Advisory
github.com / Stuk/jszip/pull/766
Third Party Advisory
snyk.io / vuln/SNYK-JAVA-ORGWEBJARS-1251499
ExploitPatchThird Party Advisory
snyk.io / vuln/SNYK-JAVA-ORGWEBJARSNPM-1251498
ExploitPatchThird Party Advisory
snyk.io / vuln/SNYK-JS-JSZIP-1251497
ExploitPatchThird Party Advisory