Vulnerabilities/

Prototype Pollution in merge-change

Severity:
High

Description

All current versions of package merge-change are vulnerable to Prototype Pollution via the utils.set function.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
merge-change
Anything's wrong? Let us know Last updated on February 01, 2023