Description
fun-map through 3.3.1 is vulnerable to Prototype Pollution. The function assocInM could be tricked into adding or modifying properties of ‘Object.prototype’ using a ‘proto’ payload.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 3.3.1
References
Related Issues
- Uncontrolled Resource Consumption in firebase - CVE-2020-7765
- Uncontrolled Resource Consumption in strapi - CVE-2020-8123
- @isaacs/brace-expansion has Uncontrolled Resource Consumption - CVE-2026-25547
- Uncontrolled Resource Consumption in markdown-it - CVE-2022-21670
You might also like:
- Tags:
- npm
- fun-map
Anything's wrong? Let us know Last updated on January 27, 2023


