Releases3
Frequency1 year 1 month
Last Release
Use 'uglify-js' instead - https://github.com/mishoo/UglifyJS2

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
= 3.13.29.8 CRITICAL

Prototype pollution vulnerability in function DEFNODE in ast.js in mishoo UglifyJS 3.13.2 via the name variable in ast.js. NOTE: the vendor considers this an invalid report.

< 2.4.249.8 CRITICAL7.5 HIGH

The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expressions, which might allow attackers to bypass security mechanisms or possibly have unspecified other impact by leveraging improperly rewritten Javascript.

<= 2.5.0, < 2.6.07.8 HIGH

The uglify-js package before 2.6.0 for Node.js allows attackers to cause a denial of service (CPU consumption) via crafted input in a parse call, aka a "regular expression denial of service (ReDoS)."