VDB
Sign up
CRITICAL9.8

GHSA-f5c9-x9j6-87qp

Prototype pollution in dotty

Quick fix

GHSA-f5c9-x9j6-87qp — dotty: upgrade to the fixed version with the command below.

npm install dotty@0.1.1

Details

Prototype pollution vulnerability in 'dotty' before version 0.1.1 allows attackers to cause a denial of service and may lead to remote code execution.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/dotty
Introduced in: 0Fixed in: 0.1.1
Fixnpm install dotty@0.1.1

References