CVE-2023-38894: Tree Kit Project Tree Kit

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

A Prototype Pollution issue in Cronvel Tree-kit v.0.7.4 and before allows a remote attacker to execute arbitrary code via the extend function.

Affected products

Published 2023-08-16. Last modified 2026-07-09.