Vulnerabilities/

Prototype pollution in emit function

Severity:
Low

Description

A prototype pollution in derby can crash the application, if the application author has atypical HTML templates that feed user input into an object key.

Attribute keys are almost always developer-controlled, not end-user-controlled, so this shouldn’t be an issue in practice for most applications.

Recommendation

Update the derby package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
derby
Anything's wrong? Let us know Last updated on April 17, 2024

This issue is available in SmartScanner Professional

See Pricing