CVE-2024-39001: AG-Grid

Medium severity, CVSS 6.3. EPSS: 0.8% chance of exploitation in the next 30 days.

ag-grid-enterprise v31.3.2 was discovered to contain a prototype pollution via the component _ModuleSupport.jsonApply. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

Affected products

  • AG-Grid AG-Grid: before 31.3.4 (fixed in 31.3.4); from 32.0.0, before 32.0.2 (fixed in 32.0.2)
  • AG-Grid AG Charts: before 9.3.2 (fixed in 9.3.2); from 10.0.0, before 10.0.2 (fixed in 10.0.2)

Published 2024-07-01. Last modified 2026-06-17.