CVE-2023-38894: Tree Kit Project Tree Kit
Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.
A Prototype Pollution issue in Cronvel Tree-kit v.0.7.4 and before allows a remote attacker to execute arbitrary code via the extend function.
Affected products
- Tree Kit Project Tree Kit: up to and including 0.7.4
Published 2023-08-16. Last modified 2026-07-09.