CRITICAL9.8
GHSA-g3vf-47fv-8f3c
MrSwitch hello.js vulnerable to prototype pollution
Quick fix
GHSA-g3vf-47fv-8f3c — hellojs: upgrade to the fixed version with the command below.
npm install hellojs@1.18.8Details
A prototype pollution vulnerability in MrSwitch hello.js prior to version 1.18.8 allows remote attackers to execute arbitrary code via `hello.utils.extend` function.
Are you affected?
Enter the version of the package you're using.