Vulnerabilities/

rollbar vulnerable to Prototype Pollution in merge()

Severity:
Medium

Description

Prototype pollution vulnerability in merge(). If application code calls rollbar.configure() with untrusted input, prototype pollution is possible.

Recommendation

Update the rollbar package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
rollbar
Anything's wrong? Let us know Last updated on October 24, 2025