VDB
Sign up
MEDIUM5.6

GHSA-6g47-63mv-qpgh

Prototype Pollution in dotty

Quick fix

GHSA-6g47-63mv-qpgh — dotty: upgrade to the fixed version with the command below.

npm install dotty@0.1.2

Details

This affects the package dotty before 0.1.2. A type confusion vulnerability can lead to a bypass of CVE-2021-25912 when the user-provided keys used in the path parameter are arrays.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/dotty
Introduced in: 0Fixed in: 0.1.2
Fixnpm install dotty@0.1.2

References