Vulnerabilities/

MrSwitch hello.js vulnerable to prototype pollution

Severity:
High

Description

A prototype pollution vulnerability in MrSwitch hello.js prior to version 1.18.8 allows remote attackers to execute arbitrary code via hello.utils.extend function.

Recommendation

Update the hellojs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
hellojs
Anything's wrong? Let us know Last updated on November 09, 2023

This issue is available in SmartScanner Professional

See Pricing