CVE-2019-18841: Chartkick Chartkick.js
High severity, CVSS 7.3. EPSS: 1.4% chance of exploitation in the next 30 days.
Chartkick.js 3.1.0 through 3.1.3, as used in the Chartkick gem before 3.3.0 for Ruby, allows prototype pollution.
Affected products
- Chartkick Chartkick.js: from 3.1.0, up to and including 3.1.3
Published 2019-11-11. Last modified 2026-06-17.