Stealjs is a JavaScript framework and build utility whose vulnerability footprint, though modest in volume, sits at an elevated prominence in the software supply chain as a dependency embedded in web applications and build pipelines. The vendor's disclosures skew strongly toward critical-severity outcomes and recur through prototype-pollution and regular-expression-complexity weaknesses that reflect the dynamic nature of JavaScript object manipulation and parsing challenges inherent to a meta-programming framework. Defenders should treat this vendor's advisories as high-priority given the severity tendency and the potential for downstream impact across dependent codebases; live exploitation activity, exposure scope, and current severity figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Stealjs over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-37257CRITICAL Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVersion variable in npm-convert.js. | Sep 15, 2022 | 9.8 | 35 | NO | NO |
CVE-2022-37264CRITICAL Prototype pollution vulnerability in stealjs steal 2.2.4 via the optionName variable in main.js. | Sep 15, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-37265CRITICAL Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js. | Sep 20, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-37258CRITICAL Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the packageName variable in npm-convert.js. | Sep 16, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-37266CRITICAL Prototype pollution vulnerability in function extend in babel.js in stealjs steal 2.2.4 via the key variable in babel.js. | Sep 15, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-37260HIGH A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the input variable in main.js. | Sep 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-37262HIGH A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the source and sourceWithComments variable in main.js. | Sep 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-37259HIGH A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the string variable in babel.js. | Sep 20, 2022 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Stealjs.
Media articles that mention a CVE ID that affects a product developed by Stealjs — matched by CVE ID, not by vendor name.