-
Notifications
You must be signed in to change notification settings - Fork 43
Open
Labels
Milestone
Description
Overview
Affected versions of this package are vulnerable to Prototype Pollution in the mergeDeep, mergeDeepWith, merge, Map.toJS, and Map.toObject functions. An attacker can inject arbitrary properties into object prototypes by supplying crafted input containing special keys, potentially leading to privilege escalation or bypassing security checks.
Introduced through
Fixed in
[email protected], @5.1.5
Action items
- upgrade [email protected] or @5.1.5 in package.json
Completion criteria
- snyk vulnerability is remediated
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
Type
Projects
Status
📥 Assigned