Mockjs is a lightweight JavaScript library used to generate mock data and intercept HTTP requests during client-side development and testing, with vulnerability exposure centered on its core mock.js product. The observed weakness class centers on prototype pollution, a structural flaw in JavaScript object-property handling that can lead to unintended modification of shared object prototypes and affect downstream behavior in applications that incorporate the library. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mockjs over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-26158HIGH All versions of the package mockjs are vulnerable to Prototype Pollution via the Util.extend function due to missing check if the attribute resolves to the object prototype. By add | Dec 8, 2023 | 8.2 | 22 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mockjs.
Media articles that mention a CVE ID that affects a product developed by Mockjs — matched by CVE ID, not by vendor name.