VDB
KO
CRITICAL 9.8

GHSA-jjff-q3q4-5hh8

@andrei-tatar/nora-firebase-common Prototype Pollution vulnerability

Details

An issue inandrei-tatar nora-firebase-common between v.1.0.41 and v.1.12.2 allows a remote attacker to execute arbitrary code via a crafted script to the updateState parameter of the updateStateInternal method.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / @andrei-tatar/nora-firebase-common
Introduced in: 1.0.41 Fixed in: 1.12.3
Fix npm install @andrei-tatar/nora-firebase-common@1.12.3

References