VDB
Sign up
HIGH7.3

GHSA-gjm5-83cw-p3p2

Prototype Pollution in extend2

Quick fix

GHSA-gjm5-83cw-p3p2 — extend2: upgrade to the fixed version with the command below.

npm install extend2@1.0.1

Details

The package extend2 before 1.0.1 are vulnerable to Prototype Pollution via the extend function due to unsafe recursive merge.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/extend2
Introduced in: 0Fixed in: 1.0.1
Fixnpm install extend2@1.0.1

References