radashi Allows Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
- Severity:
- Medium
Description
This is a prototype pollution vulnerability. It impacts users of the set function within the Radashi library.
Recommendation
Update the radashi package to the latest compatible version. Followings are version details:
- Affected version(s): < 12.5.1
- Patched version(s): 12.5.1
References
Related Issues
- mathjs Allows Improperly Controlled Modification of Dynamically-Determined Object Attributes - CVE-2026-41139
- Improperly Controlled Modification of Object Prototype Attributes - Vulnerability
- Improperly Controlled Modification of Dynamically-Determined Object Attributes in utilitify - CVE-2019-10808
- Improperly Controlled Modification of Dynamically-Determined Object Attributes in vega-util - CVE-2019-10806
You might also like:
- Tags:
- npm
- radashi
Anything's wrong? Let us know Last updated on May 27, 2025


