CVE-2022-37257
Critical · CVSS 9.8stealjs steal — Prototype Pollution
- CVSS
- 9.8
- nvd
- EPSS
- 1.11%
- 62th pct
- KEV
- No
- Class
- oss containerizable
- CWE-1321
Description
Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVersion variable in npm-convert.js.
Search profile — drives PoC discovery
Symbols convertLaternpm-convert.jsrequestedVersionext/npm-convert.js
Keywords CVE-2022-37257stealjsstealprototype pollutionconvertLaternpm-convert.jsrequestedVersionCWE-1321
Versions: 2.2.4
Affected packages
| npm | steal | 0 → ∞ |
References
- https://github.com/stealjs/steal/blob/c9dd1eb19ed3f97aeb93cf9dcea5d68ad5d0ced9/ext/npm-convert.js#L362
- https://github.com/stealjs/steal/blob/c9dd1eb19ed3f97aeb93cf9dcea5d68ad5d0ced9/ext/npm-convert.js#L371
- https://github.com/stealjs/steal/issues/1526
- http://steal.com
- http://stealjs.com
- https://github.com/stealjs/steal/blob/c9dd1eb19ed3f97aeb93cf9dcea5d68ad5d0ced9/ext/npm-convert.js#L362
- https://github.com/stealjs/steal/blob/c9dd1eb19ed3f97aeb93cf9dcea5d68ad5d0ced9/ext/npm-convert.js#L371
- https://github.com/stealjs/steal/issues/1526
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T12:30:39.000Z