Vulnerabilities/

Prototype Pollution in immer

Severity:
High

Description

This affects the package immer before 9.0.6. A type confusion vulnerability can lead to a bypass of CVE-2020-28477 when the user-provided keys used in the path parameter are arrays.

Recommendation

Update the immer package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
immer
Anything's wrong? Let us know Last updated on April 30, 2024