CRITICAL9.8
GHSA-33f9-j839-rf8h
Prototype Pollution in immer
Quick fix
GHSA-33f9-j839-rf8h — immer: upgrade to the fixed version with the command below.
npm install immer@9.0.6Details
This affects the package immer before 9.0.6. A type confusion vulnerability can lead to a bypass of CVE-2020-28477 when the user-provided keys used in the path parameter are arrays. In particular, this bypass is possible because the condition `(p === "__proto__" || p === "constructor")` in `applyPatches_` returns false if `p` is `['__proto__']` (or `['constructor']`). The `===` operator (strict equality operator) returns false if the operands have different type.
Are you affected?
Enter the version of the package you're using.