The Plist Project maintains a library for property list serialization and deserialization, a narrowly scoped component that appears across various software ecosystems and tooling where configuration and data exchange depend on plist parsing. The observed vulnerability signal centers on prototype pollution, a weakness arising from unsafe handling of object properties during deserialization that can allow untrusted input to modify shared object prototypes. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Plist Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-22912CRITICAL Prototype pollution vulnerability via .parse() in Plist before v3.0.4 allows attackers to cause a Denial of Service (DoS) and may lead to remote code execution. | Feb 17, 2022 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Plist Project.
Media articles that mention a CVE ID that affects a product developed by Plist Project — matched by CVE ID, not by vendor name.