Hello.Js Project maintains a lightweight JavaScript authentication library focused on OAuth and social login integration across web applications. The recurring vulnerability pattern centers on client-side input-handling weaknesses, particularly cross-site scripting and prototype-pollution flaws that arise from the library's role in processing and normalizing third-party identity provider responses. Current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hello.Js Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7741CRITICAL This affects the package hellojs before 1.18.6. The code get the param oauth_redirect from url and pass it to location.assign without any check and sanitisation. So we can simply p | Oct 6, 2020 | 9.9 | 29 | NO | NO |
CVE-2021-26505CRITICAL Prototype pollution vulnerability in MrSwitch hello.js version 1.18.6, allows remote attackers to execute arbitrary code via hello.utils.extend function. | Aug 11, 2023 | 9.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hello.Js Project.
Media articles that mention a CVE ID that affects a product developed by Hello.Js Project — matched by CVE ID, not by vendor name.