CVE-2022-25296: Bodymen Project Bodymen
High severity, CVSS 7.3. EPSS: 1% chance of exploitation in the next 30 days.
The package bodymen from 0.0.0 are vulnerable to Prototype Pollution via the handler function which could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload. **Note:** This vulnerability derives from an incomplete fix to [CVE-2019-10792](https://security.snyk.io/vuln/SNYK-JS-BODYMEN-548897)
Affected products
- Bodymen Project Bodymen: up to and including 1.1.1
Published 2022-03-17. Last modified 2026-06-17.