Vulnerabilities/

Prototype Pollution in undefsafe

Severity:
Medium

Description

undefsafe before 2.0.3 is vulnerable to Prototype Pollution. The ‘a’ function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.

Recommendation

Update the undefsafe package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
undefsafe
Anything's wrong? Let us know Last updated on February 01, 2023