CVE-2024-57081

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Feb 5, 2025
Updated: Feb 6, 2025
CWE ID 1321

Summary

CVE-2024-57081 is a new vulnerability affecting the lib.fromQuery function in underscore-contrib version 0.3.0. Attackers can exploit this prototype pollution flaw to cause a Denial of Service (DoS) by supplying specially crafted payloads to the function. The vulnerability arises due to insufficient input validation, allowing attackers to inject malicious data beyond the intended boundaries, ultimately leading to unintended function behavior and system instability. This issue poses a significant risk for applications that rely on underscore-contrib for query string parsing and should be addressed promptly by applying the available patch or update.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share