Description
This affects all versions of package decal. The vulnerability is in the extend function.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 2.1.3
References
- GHSA-j32x-j8pj-pg2h
- snyk.io
- www.npmjs.com
- CVE-2020-28450
- CWE-1321
- CWE-400
- CWE-94
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- Prototype Pollution in decal - decal - CVE-2020-28449
- Prototype pollution vulnerability in 'libnested - CVE-2020-28283
- Prototype Pollution in field - CVE-2020-28269
- Prototype pollution in controlled-merge - CVE-2020-28268
You might also like:
- Tags:
- npm
- decal
Anything's wrong? Let us know Last updated on September 05, 2023


