Loading HuntDB...

GHSA-v9mx-4pqq-h232

GitHub Security Advisory

Bun has an Application-level Prototype Pollution vulnerability in the runtime native API for Glo

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Versions of the package bun before 1.1.30 are vulnerable to Prototype Pollution due to improper input sanitization. An attacker can exploit this vulnerability through Bun's APIs that accept objects.

Affected Packages

npm bun
Affected versions: 0 (fixed in 1.1.30)

Related CVEs

Key Information

GHSA ID
GHSA-v9mx-4pqq-h232
Published
December 18, 2024 6:30 AM
Last Modified
December 18, 2024 4:56 PM
CVSS Score
5.0 /10
Primary Ecosystem
npm
Primary Package
bun
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 24, 2025 6:42 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.