SandboxJS is a JavaScript sandboxing library. Prior to 0.8.27, SanboxJS does not properly restrict __lookupGetter__ whic
vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-r
Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Prior to 2.9.6, 2.10.5, 2.11
deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. Vers
n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with pe
n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with pe
The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to 02 January 2025, an authentication bypass vul
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
set-in provides the set value of nested associative structure given array of keys. A prototype pollution vulnerability e
oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1.
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Po
flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled s
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.25, t
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Starting in version 2.0.39
npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js().
NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user
exceljs through 4.4.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto_
Qwik is a performance focused javascript framework. Prior to version 1.19.0, a prototype pollution vulnerability exists
MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions
ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, `apos.util.se
Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missi
i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno
`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.31, a sandbox escape vulnerability allows sandboxed code to m
deepHas provides a test for the existence of a nested object key and optionally returns that key. A prototype pollution
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to
n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated use
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the xml2js
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated use
Style Dictionary, a build system for creating cross-platform styles, has a prototype pollution vulnerability starting in
Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticat
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vuln
Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of
Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Mo
18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno.
AdonisJS is a TypeScript-first web framework. From 10.1.3 until 10.1.5 and 11.0.3, AdonisJS @adonisjs/bodyparser incompl
n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with permission to create or
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 3.3.8 until 4.5.6, the
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pol
Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Prototype Pollution via the jsondiffpatch.patch() a
RVF (formerly Remix Validated Form) provides easy form validation and state management for React. From 6.0.0 to before 6
deepobj provides get, set, delete deep objects in javascript. Prior to 1.0.3, prototype pollution is possible when prope
form-data-objectizer converts FormData to object. Prior to 1.0.1, form-data-objectizer walks bracket-notation form keys
parse-nested-form-data is a tiny node module for parsing FormData by name into objects and arrays. Prior to version 1.0.
Gestor de Oferta is a web application for managing mobility service offerings. Prior to 20260509.0340.15, @tmlmobilidade
piscina is a node.js worker pool implementation. Prior to 6.0.0-rc.2, 5.2.0, and 4.9.3, piscina's constructor and run()
Swiper is a free and mobile touch slider with hardware accelerated transitions and native behavior. Versions 6.5.1 throu
A State Pollution vulnerability was discovered in the TON Virtual Machine (TVM) before v2025.04. The issue exists in the
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.13
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the
Frequently Asked Questions
What is CWE-1321?
CWE-1321 (CWE-1321) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-1321?
There are 145 CVE records associated with CWE-1321 in our database. Of these, 24 are critical severity, 50 are high severity, and 50 are medium severity.
How can I protect against CWE-1321 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-1321 using AI-powered security agents.
Detect CWE-1321 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-1321 vulnerabilities across your infrastructure.
Get Started