Vulnerabilities/

csvjson vulnerable to prototype injection

Severity:
High

Description

A Prototype Pollution vulnerability in the toCsv function of csvjson versions thru 5.1.0 allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
csvjson
Anything's wrong? Let us know Last updated on September 26, 2025

This issue is available in SmartScanner Professional

See Pricing