VDB
Sign up
CRITICAL9.8

GHSA-2w3f-9w3q-qw77

Prototype Pollution in config-handler

Details

All versions of package config-handler are vulnerable to Prototype Pollution when loading config files.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/config-handler
Introduced in: 0

No fixed version published yet for config-handler (npm). Pin to a known-safe version or switch to an alternative.

References