Skratchdot develops a narrowly scoped utility library for object-path manipulation, where reported vulnerabilities center on prototype-pollution flaws that can arise from improper handling of object attributes during path traversal operations. This weakness class is characteristic of JavaScript libraries that recursively modify or access nested object structures without sufficient validation of property names. Current vulnerability counts and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Skratchdot over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-23507CRITICAL The package object-path-set before 1.0.2 are vulnerable to Prototype Pollution via the setPath method, as it allows an attacker to merge object prototypes into it. *Note:* This vul | Feb 4, 2022 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Skratchdot.
Media articles that mention a CVE ID that affects a product developed by Skratchdot — matched by CVE ID, not by vendor name.