CVE-2023-26133: Progressbar.js Project Progressbar.js

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

All versions of the package progressbar.js are vulnerable to Prototype Pollution via the function extend() in the file utils.js.

Affected products

Published 2023-06-12. Last modified 2026-06-17.