Description
The software receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
Recommendation
Update the think-config package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.1.3
- Patched version(s): 1.1.3
References
Related Issues
- radashi Allows Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') - CVE-2025-48054
- mathjs Allows Improperly Controlled Modification of Dynamically-Determined Object Attributes - CVE-2026-41139
- Improperly Controlled Modification of Dynamically-Determined Object Attributes in vega-util - CVE-2019-10806
- Improperly Controlled Modification of Dynamically-Determined Object Attributes in utilitify - CVE-2019-10808
You might also like:
- Tags:
- npm
- think-config
Anything's wrong? Let us know Last updated on January 09, 2023


