Vulnerabilities/

node-gettext vulnerable to Prototype Pollution

Severity:
High

Description

All versions of the package node-gettext are vulnerable to Prototype Pollution via the addTranslations() function in gettext.js due to improper user input sanitization.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
node-gettext
Anything's wrong? Let us know Last updated on November 18, 2024

This issue is available in SmartScanner Professional

See Pricing