jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
CVSS Details
- CVSS 3.1 Base Score: 10
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Atlassian Bitbucket | — | Upgrade Atlassian Bitbucket to the latest version | Nov 19, 2025 | Nov 18, 2025 |
| Debian | — | No solution existsUpgrade requirejs | May 15, 2025 | Jul 1, 2024 |
| Suse | — | Upgrade system-user-pgadminUpgrade pgadmin4-cloudUpgrade pgadmin4-desktopUpgrade pgadmin4-docUpgrade pgadmin4Upgrade pgadmin4-web-uwsgi | Dec 5, 2025 | Oct 29, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub