CVE-2021-42581 describes a prototype poisoning vulnerability in Ramda 0.27.0 and earlier, specifically within the mapObjIndexed function, which affects the ramdajs ramda library. This critical vulnerability (CVSS 9.1) allows attackers to compromise application integrity or availability by providing a specially crafted object containing a "__proto__" property as an argument, though the vendor disputes the severity. Despite its high severity, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.27.0CPE matchmatch criteria | cpe:2.3:a:ramdajs:ramda:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.