CVE-2023-38894 | Cronvel Tree-kit up to 0.7.4 extend prototype pollution (EUVD-2023-2216)
A vulnerability, which was classified as critical, has been found in Cronvel Tree-kit up to 0.7.4. Affected by this issue is the function extend. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution').
This vulnerability is handled as CVE-2023-38894. The attack may be launched remotely. There is no exploit available.