Vulnerabilities/

content-security-policy-parser Prototype Pollution Vulnerability May Lead to RCE

Severity:
High

Description

A prototype pollution vulnerability exists in versions 0.5.0 and earlier, wherein if you provide a policy name called __proto__ you can override the Object prototype.

Recommendation

Update the content-security-policy-parser package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
content-security-policy-parser
Anything's wrong? Let us know Last updated on August 12, 2025