VDB
Sign up
MEDIUM5.6

GHSA-67mq-h2r9-rh2m

Prototype pollution in multi-ini

Quick fix

GHSA-67mq-h2r9-rh2m — multi-ini: upgrade to the fixed version with the command below.

npm install multi-ini@2.1.2

Details

This affects the package multi-ini before 2.1.2. It is possible to pollute an object's prototype by specifying the constructor.proto object as part of an array. This is a bypass of CVE-2020-28448.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/multi-ini
Introduced in: 0Fixed in: 2.1.2
Fixnpm install multi-ini@2.1.2

References