Vulnerabilities/

Prototype pollution in json8

Severity:
High

Description

This affects the package json8 before 1.0.3. The function adds in the target object the property specified in the path, however it does not properly check the key being set, leading to a prototype pollution.

Recommendation

Update the json8 package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
json8
Anything's wrong? Let us know Last updated on February 01, 2023