VDB
Sign up
CRITICAL9.8

GHSA-93q5-3xpc-8vg3

steal vulnerable to Prototype Pollution via requestedVersion variable

Details

Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal via the requestedVersion variable in the npm-convert.js file.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/steal
Introduced in: 0

No fixed version published yet for steal (npm). Pin to a known-safe version or switch to an alternative.

References