VDB
Sign up
HIGH7.5

GHSA-66rh-8fw6-59q6

assign-deep Vulnerable to Prototype Pollution

Quick fix

GHSA-66rh-8fw6-59q6 — assign-deep: upgrade to the fixed version with the command below.

npm install assign-deep@0.4.8

Details

Versions of `assign-deep` prior to 1.0.1 and 0.4.8 are vulnerable to Prototype Pollution. The `assign` function fails to validate which Object properties it updates. This allows attackers to modify the prototype of Object, causing the addition or modification of an existing property on all objects.

## Recommendation

Upgrade to versions 1.0.1, 0.4.8, or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/assign-deep
Introduced in: 0Fixed in: 0.4.8
Fixnpm install assign-deep@0.4.8
npm/assign-deep
Introduced in: 1.0.0Fixed in: 1.0.1
Fixnpm install assign-deep@1.0.1

References