Description
Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to missing check if the attribute resolves to the object prototype.
Recommendation
Update the uplot package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.6.31
- Patched version(s): 1.6.31
References
Related Issues
- njwt Prototype Pollution vulnerability - CVE-2024-34273
- vue-i18n has cross-site scripting vulnerability with prototype pollution (GHSA-9r9m-ffp6-9x4v) 2 - CVE-2024-52809
- vue-i18n has cross-site scripting vulnerability with prototype pollution (GHSA-9r9m-ffp6-9x4v) 3 - CVE-2024-52809
- node-opcua-alarm-condition prototype pollution vulnerability - CVE-2024-57086
- Tags:
- npm
- uplot
Anything's wrong? Let us know Last updated on October 01, 2024