VDB
Sign up
HIGH8.6

GHSA-92v9-xh2q-fq9f

Prototype Pollution in cookiex/deep

Quick fix

GHSA-92v9-xh2q-fq9f — @cookiex/deep: upgrade to the fixed version with the command below.

npm install @cookiex/deep@0.0.7

Details

The npm @cookiex/deep package before version 0.0.7 has a prototype pollution vulnerability. The global proto object can be polluted using the __proto__ object.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@cookiex/deep
Introduced in: 0Fixed in: 0.0.7
Fixnpm install @cookiex/deep@0.0.7

References