VDB
Sign up
HIGH7.5

GHSA-9mx2-prfp-8hqp

Prototype Pollution in simpl-schema

Quick fix

GHSA-9mx2-prfp-8hqp — simpl-schema: upgrade to the fixed version with the command below.

npm install simpl-schema@1.10.2

Details

This affects the package simpl-schema before 1.10.2. Attacker controlled input into a schema could result in remote code execution within the scope of the surrounding application.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/simpl-schema
Introduced in: 0Fixed in: 1.10.2
Fixnpm install simpl-schema@1.10.2

References