UglifyJS is a widely embedded JavaScript minification and compression tool that appears across numerous build pipelines and development toolchains, creating an outsized supply-chain exposure relative to its narrow product scope. The durable signal in its vulnerability profile centers on prototype-pollution weaknesses, a class of object-manipulation flaws that can propagate through downstream applications consuming untrusted or specially crafted input during the minification process. Current severity, exploitation activity, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Uglifyjs Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-37598CRITICAL Prototype pollution vulnerability in function DEFNODE in ast.js in mishoo UglifyJS 3.13.2 via the name variable in ast.js. NOTE: the vendor considers this an invalid report. | Oct 20, 2022 | 9.8 | 31 | NO | NO |
CVE-2015-8857CRITICAL The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expressions, which might allow attackers to bypass security | Jan 23, 2017 | 9.8 | 31 | NO | NO |
CVE-2015-8858HIGH The uglify-js package before 2.6.0 for Node.js allows attackers to cause a denial of service (CPU consumption) via crafted input in a parse call, aka a "regular expression denial o | Jan 23, 2017 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Uglifyjs Project.
Media articles that mention a CVE ID that affects a product developed by Uglifyjs Project — matched by CVE ID, not by vendor name.