Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2021-44906: Minimist 1.2.5: Uncontrolled user input can corrupt data

CVE-2021-44906 · published 4 years ago
Summary

The minimist library for parsing query strings can be tricked into allowing malicious input to modify its internal data. This can lead to unexpected behavior or crashes in applications that use minimist. Update to a fixed version of minimist to prevent this issue.

What to do
  • Update ljharb minimist to version 1.2.6.
  • Update ljharb minimist to version 0.2.4.
  • Update ljharb minimist to version 1.1.3-aikido.2.
  • Update rootio @rootio/minimist to version 1.1.3-root.io.2.
  • Update ljharb minimist to version 0.0.8-aikido.1.
  • Update rootio @rootio/minimist to version 0.0.8-root.io.1.
  • Update substack minimist to version 1.2.6 or later.
Affected software
Ecosystem VendorProductAffected versions
npm ljharb minimist >= 1.0.0, < 1.2.6
< 0.2.4
Fix: upgrade to 1.2.6
– substack minimist < 1.2.6
cpe:2.3:a:substack:minimist:*:*:*:*:*:node.js:*:*
Root:npm ljharb minimist < 1.1.3-aikido.2
< 0.0.8-aikido.1
Fix: upgrade to 1.1.3-aikido.2
Root:npm rootio @rootio/minimist < 1.1.3-root.io.2
< 0.0.8-root.io.1
Fix: upgrade to 1.1.3-root.io.2
Original advisory text
Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
Severity
9.8 Critical
CVSS 3.1: 9.8 (GHSA)
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS 5%
Type
CWE-1321Prototype Pollution
Timeline
Published17 Mar 2022
Updated25 Sep 2026
First seen6 Mar 2026
Track software like this
Free during beta