VDB
KO
MEDIUM 5.3

GHSA-45rm-2893-5f49

liquidjs may leak properties of a prototype

Details

The package liquidjs before 10.0.0 is vulnerable to Information Exposure when `ownPropertyOnly` parameter is set to `False`, which results in leaking properties of a prototype. Workaround For versions 9.34.0 and higher, an option to disable this functionality is provided.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / liquidjs
Introduced in: 0 Fixed in: 10.0.0
Fix npm install liquidjs@10.0.0

References