CVE-2024-29650
JavaScript vulnerability analysis and mitigation

Overview

A prototype pollution vulnerability was discovered in @thi.ng/paths module versions 5.1.62 and earlier, identified as CVE-2024-29650. The vulnerability allows remote attackers to execute arbitrary code via the mutIn and mutInManyUnsafe components (NVD, GitHub Gist).

Technical details

The vulnerability exists in the mutIn and mutInManyUnsafe functions where properties of the source are assigned to the destination without proper verification of the property content and ownership. The issue occurs when paths.mutIn is invoked with a polluted proto property, which is passed as an argument from mutIn() in mut-in.js to defMutator() in mutator.js and then assigned to the destination. This allows manipulation of the prototype of an object, potentially affecting the behavior of all objects inheriting from the affected prototype (GitHub Gist). The vulnerability has been assigned a CVSS v3.1 base score of 9.8 CRITICAL (NVD).

Impact

A successful exploitation of this vulnerability could allow attackers to manipulate application logic, potentially leading to denial of service, remote code execution, or privilege escalation attacks. The vulnerability affects all objects sharing the same prototype, meaning a single successful attack could impact multiple objects across the application (GitHub Gist, Snyk Learn).

Exploitability

The vulnerability can be exploited by providing malicious input through the special properties proto or constructor.prototype of the built-in Object.prototype. A proof of concept demonstrates successful exploitation by using paths.mutIn or paths.mutInManyUnsafe with a polluted proto property (GitHub Gist).

Mitigation and workarounds

Users should upgrade to version 5.1.63 or newer of the @thi.ng/paths package to address this vulnerability (GitHub Gist).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77415CRITICAL9.3
  • JavaScript logoJavaScript
  • jsonata
NoYesAug 21, 2026
CVE-2026-77414CRITICAL9.3
  • JavaScript logoJavaScript
  • jsonata
NoYesAug 21, 2026
CVE-2026-77413CRITICAL9.3
  • JavaScript logoJavaScript
  • jsonata
NoYesAug 21, 2026
CVE-2026-63421HIGH7.5
  • JavaScript logoJavaScript
  • @keystone-6/core
NoYesAug 21, 2026
CVE-2026-53509MEDIUM5.7
  • JavaScript logoJavaScript
  • @aborruso/ckan-mcp-server
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management