Description
[email protected], the latest published version at the time of testing, appears to be vulnerable to prototype pollution through the public extend() utility exported from the package root.
Recommendation
Update the quasar package to the latest compatible version. Followings are version details:
- Affected version(s): <= 2.21.4
- Patched version(s): 2.22.0
References
Related Issues
- Mermaid configuration APIs allow prototype pollution - CVE-2026-71438
- CASL Ability is Vulnerable to Prototype Pollution - CVE-2026-1774
- Mermaid Architecture diagrams are vulnerable to prototype pollution - CVE-2026-71437
- set-in Affected by Prototype Pollution - CVE-2026-26021
You might also like:
- Tags:
- npm
- quasar
Anything's wrong? Let us know Last updated on August 13, 2026


