Description
flat helps flatten/unflatten nested Javascript objects. A vulnerability, which was classified as critical, was found in hughsk flat up to 5.0.0. This affects the function unflatten of the file index.js. The manipulation leads to improperly controlled modification of object prototype attributes (‘prototype pollution’).
Recommendation
Update the flat package to the latest compatible version. Followings are version details:
Affected version(s): **= 5.0.0 >= 4.0.0, < 4.0.2 = 3.0.0 >= 2.0.0, < 2.0.2 < 1.6.2** Patched version(s): **5.0.1 4.0.2 3.0.1 2.0.2 1.6.2**
References
Related Issues
- datatables.net vulnerable to Prototype Pollution due to incomplete fix - CVE-2020-28458
- TypeORM vulnerable to MAID and Prototype Pollution - CVE-2020-8158
- dset vulnerable to prototype pollution - CVE-2020-28277
- keyget vulnerable to prototype pollution - CVE-2020-28272
You might also like:
- Tags:
- npm
- flat
Anything's wrong? Let us know Last updated on January 21, 2026


