Description
All current versions of package merge-change are vulnerable to Prototype Pollution via the utils.set function.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.8.1
References
Could your website be exposed too?
SmartScanner can check your website for Prototype Pollution in merge-change and gives you actionable findings to investigate.
Start a free scanRelated Issues
- @ianwalter/merge Prototype Pollution via `merge` function - CVE-2021-23397
- Prototype Pollution in the merge and clone helper methods - CVE-2021-39227
- merge vulnerable to Prototype Pollution - CVE-2021-3645
- json-schema is vulnerable to Prototype Pollution - CVE-2021-3918
You might also like:
See something that needs correcting? Let us knowUpdated February 01, 2023


