Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
spencermountain compromise Public Root API extend.js nlp.extend prototype pollution
Vulnerability Description
A vulnerability was identified in spencermountain compromise up to 14.15.1. Affected is the function nlp.extend of the file src/API/extend.js of the component Public Root API. The manipulation of the argument plugin leads to improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is b4644ab7179700df0607521f61c1ee9b5f78d89d. Applying a patch is the recommended action to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
CWE-1321
Vulnerability Title
spencermountain compromise 输入验证错误漏洞
Vulnerability Description
spencermountain compromise是spencermountain公司开源的一款轻量级的 JavaScript 自然语言处理库,专注于将文本快速转换为可操作的结构化数据,支持词性标注、实体识别、文本变换等功能,体积仅约 250KB,可在浏览器和 Node.js 中运行。 spencermountain compromise 14.15.1及之前版本存在安全漏洞,该漏洞源于对文件src/API/extend.js中参数plugin的错误操作,导致对对象原型属性的修改控制不当,攻击者可能通过
CVSS Information
N/A
Vulnerability Type
N/A