CRITICAL9.8
GHSA-5p42-m6f3-hpmj
tree-kit Prototype Pollution vulnerability
Quick fix
GHSA-5p42-m6f3-hpmj — tree-kit: upgrade to the fixed version with the command below.
npm install tree-kit@0.7.5Details
A Prototype Pollution issue in Cronvel Tree-kit v.0.7.4 and before allows a remote attacker to execute arbitrary code via the extend function.
Are you affected?
Enter the version of the package you're using.