Springtree's vulnerability footprint centers narrowly on the madlib-object-utils library, a utility component whose disclosures recur around prototype-pollution flaws affecting object-attribute handling in JavaScript environments. This represents a focused, application-layer weakness class rather than a broad infrastructure trend; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Springtree over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7701CRITICAL madlib-object-utils before 0.1.7 is vulnerable to Prototype Pollution via setValue. | Aug 14, 2020 | 9.8 | 32 | NO | NO |
CVE-2022-24279HIGH The package madlib-object-utils before 0.1.8 are vulnerable to Prototype Pollution via the setValue method, as it allows an attacker to merge object prototypes into it. *Note:* Thi | Apr 15, 2022 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Springtree.
Media articles that mention a CVE ID that affects a product developed by Springtree — matched by CVE ID, not by vendor name.