Aurelia-Path < 1.1.7 - Prototype Pollution
CVE-2021-41097
Verified
Description
Aurelia-path before 1.1.7 contains a prototype pollution caused by parsing malicious URL parameters, letting attackers modify Object.prototype, exploit requires the application to parse user-controlled URLs.
Severity
High
CVSS Score
7.5
Affected Product
path
Published Date
January 28, 2026
Template Author
0x_akoko
CVE-2021-41097.yaml
7.5Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
CWE ID:
cwe-1321
Remediation Steps
Aurelia-path parseQueryString function was found vulnerable to prototype pollution via crafted __proto__ URL parameters.