Vulnerabilities/

rangy vulnerable to Prototype Pollution

Severity:
High

Description

All versions of the package rangy are vulnerable to Prototype Pollution when using the extend() function in file rangy-core.js.The function uses recursive merge which can lead an attacker to modify properties of the Object.prototype.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
rangy
Anything's wrong? Let us know Last updated on March 03, 2023

This issue is available in SmartScanner Professional

See Pricing