Progressbar.js is a lightweight JavaScript library for rendering animated progress bars in web applications, with a narrow product focus centered on the eponymous progressbar.js component. The observed vulnerability exposure reflects a structural weakness in the library's object-prototype handling, specifically prototype-pollution conditions that can arise in JavaScript libraries when user input insufficiently validates modifications to inherited properties. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Progressbar.Js Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-26133CRITICAL All versions of the package progressbar.js are vulnerable to Prototype Pollution via the function extend() in the file utils.js.
| Jun 12, 2023 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Progressbar.Js Project.
Media articles that mention a CVE ID that affects a product developed by Progressbar.Js Project — matched by CVE ID, not by vendor name.