Eggjs is a Node.js web application framework with a small but strategically embedded presence in development and deployment tooling, exposing an attack surface centered on command execution and object manipulation. Its durable vulnerability signal reflects weaknesses in command injection, OS command injection, and prototype pollution that recur across build and scripting components such as egg-scripts, reflecting the risks inherent in framework-level tooling that processes user input or configuration. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eggjs over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-3786CRITICAL A command injection vulnerability in egg-scripts <v2.8.1 allows arbitrary shell command execution through a maliciously crafted command line argument. | Aug 24, 2018 | 9.8 | 36 | NO | NO |
CVE-2021-23568CRITICAL The package extend2 before 1.0.1 are vulnerable to Prototype Pollution via the extend function due to unsafe recursive merge. | Jan 10, 2022 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eggjs.
Media articles that mention a CVE ID that affects a product developed by Eggjs — matched by CVE ID, not by vendor name.