VDB
Sign up
CRITICAL9.8

GHSA-9x7m-9hpg-xxmw

Prototype Pollution in putil-merge

Quick fix

GHSA-9x7m-9hpg-xxmw — putil-merge: upgrade to the fixed version with the command below.

npm install putil-merge@3.7.0

Details

Prototype pollution vulnerability in 'putil-merge' versions1.0.0 through 3.6.6 allows attacker to cause a denial of service and may lead to remote code execution.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/putil-merge
Introduced in: 1.0.0Fixed in: 3.7.0
Fixnpm install putil-merge@3.7.0

References