PT-2025-5771 · Unknown · Module-From-String

Published

2025-02-05

·

Updated

2025-02-06

·

CVE-2024-57072

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: module-from-string version 3.3.1
Description: A prototype pollution in the lib.requireFromString function allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
Recommendations: For module-from-string version 3.3.1, consider disabling the lib.requireFromString function as a temporary workaround until a patch is available. Restrict access to this function to minimize the risk of exploitation. Avoid using crafted payloads in the affected function until the issue is resolved.

Fix

DoS

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2024-57072
GHSA-Q5J8-9M9G-X2JH

Affected Products

Module-From-String