CVE-2019-18841: Chartkick Chartkick.js

High severity, CVSS 7.3. EPSS: 1.4% chance of exploitation in the next 30 days.

Chartkick.js 3.1.0 through 3.1.3, as used in the Chartkick gem before 3.3.0 for Ruby, allows prototype pollution.

Affected products

  • Chartkick Chartkick.js: from 3.1.0, up to and including 3.1.3

Published 2019-11-11. Last modified 2026-06-17.