Vulnerabilities/

robinweser fast-loops vulnerable to prototype pollution

Severity:
High

Description

robinweser fast-loops v1.1.3 was discovered to contain a prototype pollution via the function objectMergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

Recommendation

Update the fast-loops package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
fast-loops
Anything's wrong? Let us know Last updated on August 09, 2024