Vulnerabilities/

Prototype pollution in json8-merge-patch

Severity:
High

Description

Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor.

Recommendation

Update the json8-merge-patch package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
json8-merge-patch
Anything's wrong? Let us know Last updated on February 01, 2023