Releases85
Frequency2 months 4 days
Last Release
Stars5.27K
A proven SVG-based JavaScript diagramming library powering exceptional UIs

CVE History

CVEPublishedCVSS v3CVSS v2
5.6 MEDIUM7.5 HIGH

This affects the package jointjs before 3.4.2. A type confusion vulnerability can lead to a bypass of CVE-2020-28480 when the user-provided keys used in the path parameter are arrays in the setByPath function.

5.9 MEDIUM5 MEDIUM

The package jointjs before 3.3.0 are vulnerable to Denial of Service (DoS) via the unsetByPath function.

7.3 HIGH7.5 HIGH

The package jointjs before 3.3.0 are vulnerable to Prototype Pollution via util.setByPath (https://resources.jointjs.com/docs/jointjs/v3.2/joint.htmlutil.setByPath). The path used the access the object's key and set the value is not properly sanitized, leading to a Prototype Pollution.