Description
This vulnerability affects all versions of package x-assign. The global proto object can be polluted using the proto object.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 0.1.4
References
Could your website be exposed too?
SmartScanner can check your website for Prototype Pollution in x-assign and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Prototype Pollution in record-like-deep-assign - CVE-2021-23402
- deep-defaults vulnerable to prototype pollution - CVE-2021-25944
- MrSwitch hello.js vulnerable to prototype pollution - CVE-2021-26505
- Prototype Pollution in dotty - dotty - CVE-2021-23624
You might also like:
See something that needs correcting? Let us knowUpdated January 27, 2023


