Description
A Prototype Pollution issue in MiguelCastillo @bit/loader v.10.0.3 allows an attacker to execute arbitrary code via the M function e argument in index.js.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 10.0.3
References
Related Issues
- Blackprint @blackprint/engine Prototype Pollution issue - CVE-2024-24294
- json-schema-ref-parser Prototype Pollution issue - CVE-2024-29651
- robinweser fast-loops vulnerable to prototype pollution - CVE-2024-39008
- Prototype pollution in ag-grid-community via the _.mergeDeep function - ag-grid-enterprise - CVE-2024-38996
You might also like:
- Tags:
- npm
- @bit/loader
Anything's wrong? Let us know Last updated on August 20, 2024


