CVE-2024-39001: AG-Grid
Medium severity, CVSS 6.3. EPSS: 0.8% chance of exploitation in the next 30 days.
ag-grid-enterprise v31.3.2 was discovered to contain a prototype pollution via the component _ModuleSupport.jsonApply. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
Affected products
- AG-Grid AG-Grid: before 31.3.4 (fixed in 31.3.4); from 32.0.0, before 32.0.2 (fixed in 32.0.2)
- AG-Grid AG Charts: before 9.3.2 (fixed in 9.3.2); from 10.0.0, before 10.0.2 (fixed in 10.0.2)
Published 2024-07-01. Last modified 2026-06-17.