Description
akbr update 1.0.0 is vulnerable to Prototype Pollution via update/index.js.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.0.0
References
Related Issues
- akbr patch-into was discovered to contain a prototype pollution via the function patchInto - CVE-2024-38991
- vue-i18n has cross-site scripting vulnerability with prototype pollution - vue-i18n - CVE-2024-52809
- jsonic was discovered to contain a prototype pollution via the function empty. - CVE-2024-38993
- @ndhoule/defaults prototype pollution - CVE-2024-57066
You might also like:
- Tags:
- npm
- @akbr/update
Anything's wrong? Let us know Last updated on July 05, 2024


