HIGH8.6
GHSA-92v9-xh2q-fq9f
Prototype Pollution in cookiex/deep
Quick fix
GHSA-92v9-xh2q-fq9f — @cookiex/deep: upgrade to the fixed version with the command below.
npm install @cookiex/deep@0.0.7Details
The npm @cookiex/deep package before version 0.0.7 has a prototype pollution vulnerability. The global proto object can be polluted using the __proto__ object.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-23442[ADVISORY]
- https://github.com/tony-tsx/cookiex-deep/issues/1[WEB]
- https://github.com/tony-tsx/cookiex-deep/commit/b5bea2b7f34a5fa9abb4446cbd038ecdbcd09c88[WEB]
- https://github.com/tony-tsx/cookiex-deep[PACKAGE]
- https://snyk.io/vuln/SNYK-JS-COOKIEXDEEP-1582793[WEB]