Description
Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to missing check if the attribute resolves to the object prototype.
Recommendation
Update the uplot
package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.6.31
- Patched version(s): 1.6.31
References
Related Issues
- tarteaucitron Cross-site Scripting (XSS) - CVE-2025-1467
- Cross site scripting in markdown-to-jsx - CVE-2024-21535
- FUXA local file inclusion vulnerability - CVE-2023-31718
- FUXA vulnerable to Local File Inclusion - CVE-2023-31716
- Tags:
- npm
- uplot
Anything's wrong? Let us know Last updated on October 01, 2024