Antfu is an open-source software publisher with a narrow product scope centered on utility libraries and tooling, where the observed vulnerability signal reflects the inherent risks of prototype-manipulation patterns in JavaScript ecosystems. The recurring weakness class is prototype pollution—a broad category of flaws that arise from improper handling of object prototype attributes and can propagate through downstream applications that depend on these utilities. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Antfu over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2972CRITICAL Prototype Pollution in GitHub repository antfu/utils prior to 0.7.3. | May 30, 2023 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Antfu.
Media articles that mention a CVE ID that affects a product developed by Antfu — matched by CVE ID, not by vendor name.