CVE-2024-21489: Leeoniya Uplot
High severity, CVSS 8.2. EPSS: 0.7% chance of exploitation in the next 30 days.
Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to missing check if the attribute resolves to the object prototype.
Affected products
- Leeoniya Uplot: before 1.6.31 (fixed in 1.6.31)
Published 2024-10-01. Last modified 2026-08-10.