VDB
Sign up
HIGH7.7

GHSA-cwx2-736x-mf6w

Prototype pollution in object-path

Quick fix

GHSA-cwx2-736x-mf6w — object-path: upgrade to the fixed version with the command below.

npm install object-path@0.11.5

Details

### Impact A prototype pollution vulnerability has been found in `object-path` <= 0.11.4 affecting the `set()` method. The vulnerability is limited to the `includeInheritedProps` mode (if version >= 0.11.0 is used), which has to be explicitly enabled by creating a new instance of `object-path` and setting the option `includeInheritedProps: true`, or by using the default `withInheritedProps` instance. The default operating mode is not affected by the vulnerability if version >= 0.11.0 is used. Any usage of `set()` in versions < 0.11.0 is vulnerable. ### Patches Upgrade to version >= 0.11.5

### Workarounds Don't use the `includeInheritedProps: true` options or the `withInheritedProps` instance if using a version >= 0.11.0.

### References [Read more about the prototype pollution vulnerability](https://codeburst.io/what-is-prototype-pollution-49482fc4b638)

### For more information If you have any questions or comments about this advisory: * Open an issue in [object-path](https://github.com/mariocasciaro/object-path)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/object-path
Introduced in: 0Fixed in: 0.11.5
Fixnpm install object-path@0.11.5

References