VDB
Sign up
HIGH

GHSA-84p7-fh9c-6g8h

Prototype Pollution in mixme

Quick fix

GHSA-84p7-fh9c-6g8h — mixme: upgrade to the fixed version with the command below.

npm install mixme@0.5.2

Details

### Impact When copying properties from a source object to a target object, the target object can gain access to certain properties of the source object and modify their content.

### Patches The problem was patch with a more agressive discovery of secured properties to filter out.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mixme
Introduced in: 0Fixed in: 0.5.2
Fixnpm install mixme@0.5.2

References