Description
Affected versions of mithril
are vulnerable to prototype pollution. The function parseQueryString
may allow a malicious user to modify the prototype of Object
, causing the addition or modification of an existing property that will exist on all objects.
Recommendation
Update the mithril
package to the latest compatible version. Followings are version details:
Affected version(s): **>= 2.0.0, < 2.0.2 < 1.1.7** Patched version(s): **2.0.2 1.1.7**
References
Related Issues
- jsPDF Denial of Service (DoS) - CVE-2025-57810
- MailDev Remote Code Execution - CVE-2024-27448
- vxe-table prototype pollution - CVE-2024-57080
- Cross-Site Scripting in jquery - CVE-2020-7656
- Tags:
- npm
- mithril
Anything's wrong? Let us know Last updated on January 09, 2023