VDB
Sign up
CRITICAL9.8

GHSA-8f8g-9j73-7p82

steal vulnerable to Prototype Pollution via optionName variable

Details

Prototype pollution vulnerability in stealjs steal 2.2.4 via the optionName variable in main.js.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/steal
Introduced in: 0

No fixed version published yet for steal (npm). Pin to a known-safe version or switch to an alternative.

References