Vulnerabilities/

Prototype Pollution in tiny-conf

Severity:
High

Description

All versions of package tiny-conf up to and including version 1.1.0 are vulnerable to Prototype Pollution via the set function.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
tiny-conf
Anything's wrong? Let us know Last updated on February 01, 2023