Description
valib through 2.0.0 allows Internal Property Tampering. A maliciously crafted JavaScript object can bypass several inspection functions provided by valib. Valib uses a built-in function (hasOwnProperty) from the unsafe user-input to examine an object.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 2.0.0
References
Related Issues
- Exposure of Sensitive Information to an Unauthorized Actor in nanoid - CVE-2021-23566
- bson-objectid contains Improper input validation - CVE-2019-19729
- websocket-driver: Resource limit bypass via message compression - CVE-2026-54490
- Sensitive Data Exposure in msrcrypto - CVE-2018-8319
You might also like:
- Tags:
- npm
- valib
Anything's wrong? Let us know Last updated on February 01, 2023


