Vulnerabilities/

ion-parser Prototype Pollution when malicious INI file submitted to application that parses with `parse`

Severity:
High

Description

This affects all versions of package ion-parser. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can be exploited further depending on the context.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
ion-parser
Anything's wrong? Let us know Last updated on January 27, 2023