Description
This affects all versions of package decal. The vulnerability is in the extend function.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 2.1.3
References
Could your website be exposed too?
SmartScanner can check your website for Prototype Pollution in decal and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Prototype Pollution in decal - decal - CVE-2020-28449
- Prototype pollution vulnerability in 'libnested - CVE-2020-28283
- Prototype Pollution in field - CVE-2020-28269
- Prototype pollution in controlled-merge - CVE-2020-28268
You might also like:
See something that needs correcting? Let us knowUpdated September 05, 2023


