VDB
Sign up
HIGH7.5

GHSA-5q53-78f2-6gf8

apidoc-core is vulnerable to prototype pollution

Details

apidoc-core is the core parser library to generate apidoc result following the apidoc-spec. A Prototype Pollution vulnerability in the preProcess function of apidoc-core versions thru 0.15.0 allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/apidoc-core
Introduced in: 0

No fixed version published yet for apidoc-core (npm). Pin to a known-safe version or switch to an alternative.

References