Vulnerabilities/

Prototype Pollution in chartkick

Severity:
High

Description

Affected versions of @polymer/polymer are vulnerable to prototype pollution. The package fails to prevent modification of object prototypes through chart options containing a payload such as {"__proto__": {"polluted": true}}. It is possible to achieve the same results if a chart loads data from a malicious server.

Recommendation

Update the chartkick package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
chartkick
Anything's wrong? Let us know Last updated on January 26, 2023

This issue is available in SmartScanner Professional

See Pricing