VDB
Sign up
MEDIUM5.6

GHSA-77xq-cpvg-7xm2

Prototype pollution in @tsed/core

Quick fix

GHSA-77xq-cpvg-7xm2 — @tsed/core: upgrade to the fixed version with the command below.

npm install @tsed/core@5.65.7

Details

This affects the package @tsed/core before 5.65.7. This vulnerability relates to the `deepExtend` function which is used as part of the utils directory. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@tsed/core
Introduced in: 0Fixed in: 5.65.7
Fixnpm install @tsed/core@5.65.7

References