{"schema_version":1,"title":"Jonschlinkert vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 14 vulnerabilities in Jonschlinkert: 1 in the last 7 days and 1 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-78847, was published on 21 September 2026.","url":"https://junglewise.ai/threats/vendors/jonschlinkert","json_url":"https://junglewise.ai/threats/vendors/jonschlinkert.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/jonschlinkert","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":0,"all_time":14,"critical":1,"exploited":0,"last_7_days":1,"last_30_days":1,"last_90_days":1,"last_365_days":1},"latest":[{"cve":"CVE-2026-78847","cvss":9.8,"epss":0.0087,"slug":"cve-2026-78847-an-issue-in-gray-matter-all-versions-verified-on-4-0-3-allows-the","title":"gray-matter arbitrary code execution via eval in JavaScript engine","severity":"critical","exploited":false,"published_at":"2026-09-21T22:16:58.863+00:00","url":"https://junglewise.ai/threats/cve-2026-78847-an-issue-in-gray-matter-all-versions-verified-on-4-0-3-allows-the"},{"cve":"CVE-2025-57328","cvss":4,"slug":"cve-2025-57328-jonschlinkert-toggle-array-prototype-pollution-in-enable-and","title":"jonschlinkert toggle-array prototype pollution in enable and disable functions","severity":"medium","exploited":false,"published_at":"2025-09-24T21:30:37+00:00","url":"https://junglewise.ai/threats/cve-2025-57328-jonschlinkert-toggle-array-prototype-pollution-in-enable-and"},{"cve":"CVE-2025-3197","cvss":3.1,"epss":0.0041,"slug":"cve-2025-3197-expand-object-prototype-pollution-in-expand-function","title":"expand-object prototype pollution in expand() function","severity":"low","exploited":false,"published_at":"2025-04-04T06:34:23+00:00","url":"https://junglewise.ai/threats/cve-2025-3197-expand-object-prototype-pollution-in-expand-function"},{"cve":"CVE-2025-25975","cvss":3.1,"epss":0.0046,"slug":"cve-2025-25975-parse-git-config-prototype-pollution-via-expandkeys","title":"parse-git-config prototype pollution via expandKeys","severity":"low","exploited":false,"published_at":"2025-03-12T21:31:29+00:00","url":"https://junglewise.ai/threats/cve-2025-25975-parse-git-config-prototype-pollution-via-expandkeys"},{"cve":"CVE-2023-26115","cvss":3.1,"epss":0.0171,"slug":"cve-2023-26115-word-wrap-regular-expression-denial-of-service","title":"word-wrap regular expression denial of service","severity":"low","exploited":false,"published_at":"2023-06-22T06:30:18+00:00","url":"https://junglewise.ai/threats/cve-2023-26115-word-wrap-regular-expression-denial-of-service"},{"cve":"CVE-2021-23440","cvss":3.1,"epss":0.0221,"slug":"cve-2021-23440-set-value-prototype-pollution-with-non-string-path-components","title":"set-value prototype pollution with non-string path components","severity":"low","exploited":false,"published_at":"2021-09-13T20:09:36+00:00","url":"https://junglewise.ai/threats/cve-2021-23440-set-value-prototype-pollution-with-non-string-path-components"},{"cve":"CVE-2014-10065","epss":0.0097,"slug":"cve-2014-10065-remarkable-content-injection-via-unescaped-javascript-protocol","title":"remarkable content injection via unescaped javascript protocol","severity":"info","exploited":false,"published_at":"2020-08-31T22:56:00+00:00","url":"https://junglewise.ai/threats/cve-2014-10065-remarkable-content-injection-via-unescaped-javascript-protocol"},{"cve":"CVE-2019-20149","cvss":3.1,"epss":0.0234,"slug":"cve-2019-20149-kind-of-validation-bypass-via-malicious-constructor-property","title":"kind-of validation bypass via malicious constructor property","severity":"low","exploited":false,"published_at":"2020-03-31T15:59:54+00:00","url":"https://junglewise.ai/threats/cve-2019-20149-kind-of-validation-bypass-via-malicious-constructor-property"},{"cve":"CVE-2019-10747","cvss":3.1,"epss":0.0248,"slug":"cve-2019-10747-set-value-prototype-pollution","title":"set-value prototype pollution","severity":"low","exploited":false,"published_at":"2019-08-27T17:43:33+00:00","url":"https://junglewise.ai/threats/cve-2019-10747-set-value-prototype-pollution"},{"cve":"CVE-2019-10745","cvss":3,"epss":0.0114,"slug":"cve-2019-10745-assign-deep-prototype-pollution-in-assign-function","title":"assign-deep prototype pollution in assign function","severity":"low","exploited":false,"published_at":"2019-08-21T16:15:13+00:00","url":"https://junglewise.ai/threats/cve-2019-10745-assign-deep-prototype-pollution-in-assign-function"},{"cve":"CVE-2019-12043","cvss":3,"slug":"cve-2019-12043-remarkable-cross-site-scripting-via-unprintable-characters-in","title":"Remarkable Cross-site Scripting via unprintable characters in URLs","severity":"low","exploited":false,"published_at":"2019-05-29T18:04:55+00:00","url":"https://junglewise.ai/threats/cve-2019-12043-remarkable-cross-site-scripting-via-unprintable-characters-in"},{"cve":"CVE-2017-16028","cvss":3,"epss":0.0135,"slug":"cve-2017-16028-randomatic-cryptographically-weak-prng","title":"randomatic cryptographically weak PRNG","severity":"low","exploited":false,"published_at":"2018-10-09T00:57:21+00:00","url":"https://junglewise.ai/threats/cve-2017-16028-randomatic-cryptographically-weak-prng"},{"cve":"CVE-2018-3723","cvss":3,"epss":0.0204,"slug":"cve-2018-3723-defaults-deep-prototype-pollution-vulnerability","title":"defaults-deep prototype pollution vulnerability","severity":"low","exploited":false,"published_at":"2018-07-26T15:18:43+00:00","url":"https://junglewise.ai/threats/cve-2018-3723-defaults-deep-prototype-pollution-vulnerability"},{"cve":"CVE-2018-3719","cvss":3.1,"slug":"cve-2018-3719-mixin-deep-prototype-pollution-via-merging-functions","title":"mixin-deep prototype pollution via merging functions","severity":"low","exploited":false,"published_at":"2018-07-26T15:10:54+00:00","url":"https://junglewise.ai/threats/cve-2018-3719-mixin-deep-prototype-pollution-via-merging-functions"}],"vendor":{"hub":true,"name":"Jonschlinkert","slug":"jonschlinkert","url":"https://junglewise.ai/threats/vendors/jonschlinkert"},"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":1,"exploited":0,"vulnerabilities":1},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-78847","cvss":9.8,"epss":0.0087,"slug":"cve-2026-78847-an-issue-in-gray-matter-all-versions-verified-on-4-0-3-allows-the","title":"gray-matter arbitrary code execution via eval in JavaScript engine","severity":"critical","exploited":false,"published_at":"2026-09-21T22:16:58.863+00:00","url":"https://junglewise.ai/threats/cve-2026-78847-an-issue-in-gray-matter-all-versions-verified-on-4-0-3-allows-the"},{"cve":"CVE-2025-57328","cvss":4,"slug":"cve-2025-57328-jonschlinkert-toggle-array-prototype-pollution-in-enable-and","title":"jonschlinkert toggle-array prototype pollution in enable and disable functions","severity":"medium","exploited":false,"published_at":"2025-09-24T21:30:37+00:00","url":"https://junglewise.ai/threats/cve-2025-57328-jonschlinkert-toggle-array-prototype-pollution-in-enable-and"},{"cve":"CVE-2019-10747","cvss":3.1,"epss":0.0248,"slug":"cve-2019-10747-set-value-prototype-pollution","title":"set-value prototype pollution","severity":"low","exploited":false,"published_at":"2019-08-27T17:43:33+00:00","url":"https://junglewise.ai/threats/cve-2019-10747-set-value-prototype-pollution"},{"cve":"CVE-2019-20149","cvss":3.1,"epss":0.0234,"slug":"cve-2019-20149-kind-of-validation-bypass-via-malicious-constructor-property","title":"kind-of validation bypass via malicious constructor property","severity":"low","exploited":false,"published_at":"2020-03-31T15:59:54+00:00","url":"https://junglewise.ai/threats/cve-2019-20149-kind-of-validation-bypass-via-malicious-constructor-property"},{"cve":"CVE-2021-23440","cvss":3.1,"epss":0.0221,"slug":"cve-2021-23440-set-value-prototype-pollution-with-non-string-path-components","title":"set-value prototype pollution with non-string path components","severity":"low","exploited":false,"published_at":"2021-09-13T20:09:36+00:00","url":"https://junglewise.ai/threats/cve-2021-23440-set-value-prototype-pollution-with-non-string-path-components"},{"cve":"CVE-2023-26115","cvss":3.1,"epss":0.0171,"slug":"cve-2023-26115-word-wrap-regular-expression-denial-of-service","title":"word-wrap regular expression denial of service","severity":"low","exploited":false,"published_at":"2023-06-22T06:30:18+00:00","url":"https://junglewise.ai/threats/cve-2023-26115-word-wrap-regular-expression-denial-of-service"},{"cve":"CVE-2025-25975","cvss":3.1,"epss":0.0046,"slug":"cve-2025-25975-parse-git-config-prototype-pollution-via-expandkeys","title":"parse-git-config prototype pollution via expandKeys","severity":"low","exploited":false,"published_at":"2025-03-12T21:31:29+00:00","url":"https://junglewise.ai/threats/cve-2025-25975-parse-git-config-prototype-pollution-via-expandkeys"},{"cve":"CVE-2025-3197","cvss":3.1,"epss":0.0041,"slug":"cve-2025-3197-expand-object-prototype-pollution-in-expand-function","title":"expand-object prototype pollution in expand() function","severity":"low","exploited":false,"published_at":"2025-04-04T06:34:23+00:00","url":"https://junglewise.ai/threats/cve-2025-3197-expand-object-prototype-pollution-in-expand-function"},{"cve":"CVE-2018-3719","cvss":3.1,"slug":"cve-2018-3719-mixin-deep-prototype-pollution-via-merging-functions","title":"mixin-deep prototype pollution via merging functions","severity":"low","exploited":false,"published_at":"2018-07-26T15:10:54+00:00","url":"https://junglewise.ai/threats/cve-2018-3719-mixin-deep-prototype-pollution-via-merging-functions"},{"cve":"CVE-2018-3723","cvss":3,"epss":0.0204,"slug":"cve-2018-3723-defaults-deep-prototype-pollution-vulnerability","title":"defaults-deep prototype pollution vulnerability","severity":"low","exploited":false,"published_at":"2018-07-26T15:18:43+00:00","url":"https://junglewise.ai/threats/cve-2018-3723-defaults-deep-prototype-pollution-vulnerability"}],"generated_at":"2026-09-28T03:07:00.154823+00:00","technologies":[]}