Cached Path Relative Project develops a focused utility addressing path-resolution vulnerabilities, with the exposure limited to its core cached_path_relative product. Live severity, exploitation, and coverage counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cached Path Relative Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-23518CRITICAL The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelativ | Jan 21, 2022 | 9.8 | 31 | NO | NO |
CVE-2018-16472HIGH A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inherited by all the JS objects thr | Nov 6, 2018 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cached Path Relative Project.
Media articles that mention a CVE ID that affects a product developed by Cached Path Relative Project — matched by CVE ID, not by vendor name.