Vulnerabilities/

uPlot Prototype Pollution vulnerability

Severity:
High

Description

Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to missing check if the attribute resolves to the object prototype.

Recommendation

Update the uplot package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
uplot
Anything's wrong? Let us know Last updated on October 01, 2024

This issue is available in SmartScanner Professional

See Pricing