CRITICAL9.8
GHSA-5pxj-mhwj-x5gv
Prototype Pollution in asciitable.js
Quick fix
GHSA-5pxj-mhwj-x5gv — asciitable.js: upgrade to the fixed version with the command below.
npm install asciitable.js@1.0.3Details
The package asciitable.js before 1.0.3 is vulnerable to Prototype Pollution via the main function.
### PoC ```js var a = require("asciitable.js"); var b = JSON.parse('{"__proto__":{"test":123}}'); a({},b); console.log({}.test) ```
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-7771[ADVISORY]
- https://github.com/victornpb/asciitable.js/pull/1[WEB]
- https://github.com/victornpb/asciitable.js/commit/8db8fc5ffa7a2a6e8596709d99b200afb53f40ab[WEB]
- https://github.com/victornpb/asciitable.js[PACKAGE]
- https://snyk.io/vuln/SNYK-JS-ASCIITABLEJS-1039799[WEB]