Vulnerabilities/

eivindfjeldstad-dot contains prototype pollution vulnerability

Severity:
Medium

Description

eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function ‘set’ could be tricked into adding or modifying properties of ‘Object.prototype’ using a ‘proto’ payload.

Recommendation

Update the @eivifj/dot package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@eivifj/dot
Anything's wrong? Let us know Last updated on July 13, 2023