Vulnerabilities/

devalue prototype pollution vulnerability

Severity:
High

Description

A string passed to devalue.parse could represent an object with a __proto__ property, which would assign a prototype to an object while allowing properties to be overwritten:

Recommendation

Update the devalue package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
devalue
Anything's wrong? Let us know Last updated on August 27, 2025

This issue is available in SmartScanner Professional

See Pricing