Product
uglifyjs project uglifyjs
3 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2022-37598
CVE-2015-8858
CVE-2015-8857
all versions
Prototype pollution vulnerability in function DEFNODE in ast.js in mishoo UglifyJS 3.13.2 via the name variable in ast.js. NOTE: t
<= 2.5.0
The uglify-js package before 2.6.0 for Node.js allows attackers to cause a denial of service (CPU consumption) via crafted input i
< 2.4.24
The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expression