Vulnerabilities/

Prototype Pollution in ts-nodash

Severity:
High

Description

ts-nodash before version 1.2.7 is vulnerable to Prototype Pollution via the Merge() function due to lack of validation input.

Recommendation

Update the ts-nodash package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
ts-nodash
Anything's wrong? Let us know Last updated on January 27, 2023

This issue is available in SmartScanner Professional

See Pricing