Schema Inspector Project develops a validation and schema-inspection utility that, despite a narrow product focus, serves data-processing and validation workflows where correctness is critical. The observed vulnerabilities reflect the product's role in parsing and validating structured input. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Schema Inspector Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10781CRITICAL In schema-inspector before 1.6.9, a maliciously crafted JavaScript object can bypass the `sanitize()` and the `validate()` function used within schema-inspector. | Jan 22, 2020 | 9.8 | 29 | NO | NO |
CVE-2021-21267HIGH Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before version 2.0.0, email address validation is vulnerable to a den | Mar 19, 2021 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Schema Inspector Project.
Media articles that mention a CVE ID that affects a product developed by Schema Inspector Project — matched by CVE ID, not by vendor name.