Description
The package object-extend from 0.0.0 through 0.5.0 is vulnerable to Prototype Pollution via object-extend.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 0.5.0
References
Related Issues
- Prototype Pollution Vulnerability in object-collider - CVE-2021-25914
- Prototype pollution vulnerability in js-extend - CVE-2021-25945
- jquery-plugin-query-object contains prototype pollution vulnerability - CVE-2021-20083
- Prototype pollution in aurelia-path - CVE-2021-41097
You might also like:
- Tags:
- npm
- object-extend
Anything's wrong? Let us know Last updated on February 03, 2023


