CVE-2024-38985: Janrywang Depath

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() method at setIn (lib/index.js:90). This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

Affected products

  • Janrywang Depath: version 1.0.6 only; version 1.1.2 only

Published 2025-03-28. Last modified 2026-06-17.