GHSA-8g4m-cjm2-96wq
Sandbox escape in notevil and argencoders-notevil
Details
This affects all versions of package notevil; all versions of package argencoders-notevil. It is vulnerable to Sandbox Escape leading to Prototype pollution. The package fails to restrict access to the main context, allowing an attacker to add or modify an object's prototype. **Note:** This vulnerability derives from an incomplete fix in [SNYK-JS-NOTEVIL-608878](https://security.snyk.io/vuln/SNYK-JS-NOTEVIL-608878). This package has been deprecated.
Are you affected?
Enter the version of the package you're using.
Affected packages
0No fixed version published yet for notevil (npm). Pin to a known-safe version or switch to an alternative.
0No fixed version published yet for argencoders-notevil (npm). Pin to a known-safe version or switch to an alternative.