Vulnerabilities/

jszip Vulnerable to Prototype Pollution

Severity:
Medium

Description

This affects the package jszip before 3.7.0. Crafting a new zip file with filenames set to Object prototype values (e.g __proto__, toString, etc) results in a returned object with a modified prototype instance.

Recommendation

Update the jszip package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
jszip
Anything's wrong? Let us know Last updated on September 21, 2023