Vulnerabilities/

flat vulnerable to Prototype Pollution

Severity:
High

Description

flat helps flatten/unflatten nested Javascript objects. A vulnerability, which was classified as critical, was found in hughsk flat up to 5.0.0. This affects the function unflatten of the file index.js. The manipulation leads to improperly controlled modification of object prototype attributes (‘prototype pollution’).

Recommendation

Update the flat package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
flat
Anything's wrong? Let us know Last updated on January 21, 2026